ZeroHour

CVE-2022-42119

CVSS 3.1
5.4 medium
EPSS
<1%p34
Published
()
Modified
Description

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

Vendors
liferay
Products
liferay portal, dxp
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.