Cross-Site Scripting Vulnerability in Liferay Portal and Liferay DXP
CVE-2022-26593

5.4MEDIUM

Key Information:

Vendor

Liferay

Vendor
CVE Published:
19 April 2022

What is CVE-2022-26593?

A cross-site scripting (XSS) vulnerability exists in the Asset module's asset categories selector of Liferay Portal versions 7.3.3 through 7.4.0 and Liferay DXP 7.3 prior to service pack 3. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the asset category name, potentially compromising the security of the affected system. Users are advised to verify and sanitize input values before processing to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.