CVE-2022-42116

A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
liferaydxp
𝑥
< 7.3
liferaydxp
7.3
liferaydxp
7.3:sp1
liferaydxp
7.3:sp2
liferaydxp
7.3:sp3
liferaydxp
7.3:update_1
liferaydxp
7.3:update_2
liferaydxp
7.3:update_3
liferaydxp
7.3:update_4
liferaydxp
7.3:update_5
liferaydxp
7.4:ga1
liferaydxp
7.4:update_1
liferaydxp
7.4:update_10
liferaydxp
7.4:update_11
liferaydxp
7.4:update_12
liferaydxp
7.4:update_13
liferaydxp
7.4:update_14
liferaydxp
7.4:update_2
liferaydxp
7.4:update_3
liferaydxp
7.4:update_4
liferaydxp
7.4:update_5
liferaydxp
7.4:update_6
liferaydxp
7.4:update_7
liferaydxp
7.4:update_8
liferaydxp
7.4:update_9
liferayliferay_portal
7.3.2 ≤
𝑥
< 7.4.3.15
𝑥
= Vulnerable software versions