CVE-2022-42121
Summary
| CVE | CVE-2022-42121 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-15 01:15:00 UTC |
| Updated | 2022-11-17 15:00:00 UTC |
| Description | A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Liferay | Dxp | 7.1 | - | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_1 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_10 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_11 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_12 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_13 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_14 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_15 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_16 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_17 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_18 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_19 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_2 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_20 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_21 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_22 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_23 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_24 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_25 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_3 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_4 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_5 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_6 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_7 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_8 | All | All |
| Application | Liferay | Dxp | 7.1 | fix_pack_9 | All | All |
| Application | Liferay | Dxp | 7.2 | - | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_1 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_10 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_11 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_12 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_13 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_14 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_15 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_2 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_3 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_4 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_5 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_6 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_7 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_8 | All | All |
| Application | Liferay | Dxp | 7.2 | fix_pack_9 | All | All |
| Application | Liferay | Dxp | 7.3 | - | All | All |
| Application | Liferay | Dxp | 7.3 | sp1 | All | All |
| Application | Liferay | Dxp | 7.3 | sp2 | All | All |
| Application | Liferay | Dxp | 7.4 | ga1 | All | All |
| Application | Liferay | Liferay Portal | All | All | All | All |
| Application | Liferay | Liferay Portal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Digital Experience Software Tailored to Your Needs | Liferay | MISC | liferay.com | |
| CVE-2022-42121 SQL injection vulnerability during page template upgrade | MISC | portal.liferay.dev | |
| [LPE-17414] LSV-961: SQL injection vulnerability during page template upgrade - Liferay Issues | MISC | issues.liferay.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 731100 Liferay Portal SQL Injection Vulnerability (CVE-2022-42121)