GHSA-r32w-v775-5952
Dashboard / Vulnerabilities / GHSA-r32w-v775-5952
Summary: Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module
Details: A Cross-site scripting (XSS) vulnerability in Document Library module before 6.0.98 from Liferay Portal (7.4.3.30 through 7.4.3.36), and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-42113, https://github.com/liferay/liferay-portal/commit/2e4d17dfe42bb3b12c96527943087cf7e4a7d57e, https://github.com/liferay/liferay-portal/commit/62797d3ada6545b12fbfb86dbb229ac9d491d2c2, https://github.com/liferay/liferay-portal, https://liferay.atlassian.net/browse/LPE-17615, https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-42113?p_r_p_assetEntryId=121613062&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121613062%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse, https://web.archive.org/web/20221019040338/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42113, http://liferay.com
Affected packages
Package
Name: com.liferay:com.liferay.document.library.web
Purl: pkg:maven/com.liferay/com.liferay.document.library.web
Affected ranges
Type: ECOSYSTEM
Events:
