Cross-Site Scripting Vulnerability in Liferay Portal and Liferay DXP
CVE-2022-26593
5.4MEDIUM
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 19 April 2022
What is CVE-2022-26593?
A cross-site scripting (XSS) vulnerability exists in the Asset module's asset categories selector of Liferay Portal versions 7.3.3 through 7.4.0 and Liferay DXP 7.3 prior to service pack 3. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the asset category name, potentially compromising the security of the affected system. Users are advised to verify and sanitize input values before processing to mitigate the risk of exploitation.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved