CVE-2022-42110
Summary
| CVE | CVE-2022-42110 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-15 00:15:00 UTC |
| Updated | 2022-11-17 14:37:00 UTC |
| Description | A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Liferay | Dxp | 7.1 | - | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_1 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_10 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_11 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_12 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_13 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_14 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_15 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_16 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_17 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_18 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_19 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_2 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_20 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_21 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_22 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_23 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_24 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_25 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_3 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_4 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_5 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_6 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_7 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_8 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_9 | All | All |
| Application | Liferay | Dxp | 7.2 | - | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_1 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_10 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_11 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_12 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_13 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_14 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_15 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_2 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_3 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_4 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_5 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_6 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_7 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_8 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_9 | All | All |
| Application | Liferay | Dxp | 7.3 | - | All | All |
| Application | Liferay | Dxp | 7.3 | sp1 | All | All |
| Application | Liferay | Dxp | 7.3 | sp2 | All | All |
| Application | Liferay | Liferay Portal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-42110 Stored XSS with announcement/alert type | MISC | portal.liferay.dev | |
| [LPE-17403] LSV-959: Stored XSS with announcement/alert type - Liferay Issues | MISC | issues.liferay.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 731102 Liferay Portal Multiple Cross-Site Scripting (XSS) Vulnerabilities