CVE-2022-38901
19.10.2022, 02:15
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Vendor | Product | Version |
---|---|---|
liferay | dxp | 7.0 ≤ 𝑥 < 7.3 |
liferay | dxp | 7.3 |
liferay | dxp | 7.3:update_1 |
liferay | dxp | 7.3:update_2 |
liferay | dxp | 7.3:update_3 |
liferay | dxp | 7.3:update_4 |
liferay | dxp | 7.3:update_5 |
liferay | dxp | 7.4:update_1 |
liferay | dxp | 7.4:update_10 |
liferay | dxp | 7.4:update_11 |
liferay | dxp | 7.4:update_12 |
liferay | dxp | 7.4:update_13 |
liferay | dxp | 7.4:update_14 |
liferay | dxp | 7.4:update_15 |
liferay | dxp | 7.4:update_16 |
liferay | dxp | 7.4:update_17 |
liferay | dxp | 7.4:update_18 |
liferay | dxp | 7.4:update_19 |
liferay | dxp | 7.4:update_2 |
liferay | dxp | 7.4:update_20 |
liferay | dxp | 7.4:update_21 |
liferay | dxp | 7.4:update_22 |
liferay | dxp | 7.4:update_23 |
liferay | dxp | 7.4:update_24 |
liferay | dxp | 7.4:update_25 |
liferay | dxp | 7.4:update_26 |
liferay | dxp | 7.4:update_27 |
liferay | dxp | 7.4:update_28 |
liferay | dxp | 7.4:update_3 |
liferay | dxp | 7.4:update_4 |
liferay | dxp | 7.4:update_5 |
liferay | dxp | 7.4:update_6 |
liferay | dxp | 7.4:update_7 |
liferay | dxp | 7.4:update_8 |
liferay | dxp | 7.4:update_9 |
liferay | liferay_portal | 7.3.5 ≤ 𝑥 ≤ 7.4.3.28 |
𝑥
= Vulnerable software versions
References