← voltar
CVE-2022-42118mediumCWE-79

CVE-2022-42118

28Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 6.1epss 1.0%
probabilidade de exploração
1.0%top 40% das CVEs
exploração observada
nãonenhuma fonte reporta
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
n/a · n/a