A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
History

Sat, 10 May 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-18T00:00:00.000Z

Updated: 2025-05-10T02:44:34.087Z

Reserved: 2022-10-03T00:00:00.000Z

Link: CVE-2022-42112

cve-icon Vulnrichment

Updated: 2024-08-03T13:03:45.719Z

cve-icon NVD

Status : Modified

Published: 2022-10-18T21:15:16.203

Modified: 2025-05-10T03:15:21.487

Link: CVE-2022-42112

cve-icon Redhat

No data.