Cross-Site Scripting Vulnerability in Liferay Portal by Liferay
CVE-2022-26597

6.1MEDIUM

Key Information:

Vendor

Liferay

Vendor
CVE Published:
25 April 2022

What is CVE-2022-26597?

A Cross-Site Scripting (XSS) vulnerability exists in the Open Graph integration of the Layout module within Liferay Portal versions 7.3.0 to 7.4.0 and Liferay DXP 7.3 prior to service pack 3. This flaw enables remote attackers to inject arbitrary web scripts or HTML into the site name, potentially compromising the integrity of the web application and the data of its users. Successful exploitation of this vulnerability could lead to a variety of malicious outcomes, including the execution of unwanted actions on behalf of users and unauthorized data access.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.