ZeroHour

CVE-2022-38901

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.

Vendors
liferay
Products
dxp, liferay portal
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.