Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42111: [LPE-17379] LSV-936: Stored XSS with a shared asset name in notification

A Cross-site scripting (XSS) vulnerability in the Sharing module’s user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.

CVE
#xss#vulnerability#web

Details

  • **Type: ** Bug

  • Status: Closed

  • **Priority: ** Minor

  • Resolution: Fixed

  • Affects Version/s: 7.2 DXP (7.2.10)

  • Component/s: None
  • CVSS Vector String:

    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Cross-site scripting (XSS) vulnerability in the Sharing module’s user notification in Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload injected into the asset’s title text field.

Activity

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda