CVE-2022-42119
EUVD-2022-4520515.11.2022, 01:15
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| liferay | liferay_portal | 7.3.5 ≤ 𝑥 ≤ 7.4.2 |
| liferay | dxp | 7.3 |
| liferay | dxp | 7.3:update_1 |
| liferay | dxp | 7.3:update_2 |
| liferay | dxp | 7.3:update_3 |
| liferay | dxp | 7.3:update_4 |
| liferay | dxp | 7.3:update_5 |
| liferay | dxp | 7.3:update_6 |
| liferay | dxp | 7.3:update_7 |
𝑥
= Vulnerable software versions
References