CVE-2022-38901
19.10.2022, 02:15
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
| Vendor | Product | Version |
|---|---|---|
| liferay | dxp | 7.0 ≤ 𝑥 < 7.3 |
| liferay | dxp | 7.3 |
| liferay | dxp | 7.3:update_1 |
| liferay | dxp | 7.3:update_2 |
| liferay | dxp | 7.3:update_3 |
| liferay | dxp | 7.3:update_4 |
| liferay | dxp | 7.3:update_5 |
| liferay | dxp | 7.4:update_1 |
| liferay | dxp | 7.4:update_10 |
| liferay | dxp | 7.4:update_11 |
| liferay | dxp | 7.4:update_12 |
| liferay | dxp | 7.4:update_13 |
| liferay | dxp | 7.4:update_14 |
| liferay | dxp | 7.4:update_15 |
| liferay | dxp | 7.4:update_16 |
| liferay | dxp | 7.4:update_17 |
| liferay | dxp | 7.4:update_18 |
| liferay | dxp | 7.4:update_19 |
| liferay | dxp | 7.4:update_2 |
| liferay | dxp | 7.4:update_20 |
| liferay | dxp | 7.4:update_21 |
| liferay | dxp | 7.4:update_22 |
| liferay | dxp | 7.4:update_23 |
| liferay | dxp | 7.4:update_24 |
| liferay | dxp | 7.4:update_25 |
| liferay | dxp | 7.4:update_26 |
| liferay | dxp | 7.4:update_27 |
| liferay | dxp | 7.4:update_28 |
| liferay | dxp | 7.4:update_3 |
| liferay | dxp | 7.4:update_4 |
| liferay | dxp | 7.4:update_5 |
| liferay | dxp | 7.4:update_6 |
| liferay | dxp | 7.4:update_7 |
| liferay | dxp | 7.4:update_8 |
| liferay | dxp | 7.4:update_9 |
| liferay | liferay_portal | 7.3.5 ≤ 𝑥 ≤ 7.4.3.28 |
𝑥
= Vulnerable software versions
References