CVE-2022-42113

EUVD-2022-45199
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Affected Products (NVD)
VendorProductVersion
liferaydxp
7.4:update_30
liferaydxp
7.4:update_31
liferaydxp
7.4:update_32
liferaydxp
7.4:update_33
liferaydxp
7.4:update_34
liferaydxp
7.4:update_35
liferaydxp
7.4:update_36
liferayliferay_portal
7.4.3.30 ≤
𝑥
< 7.4.3.37
𝑥
= Vulnerable software versions