Headline
CVE-2022-42111: [LPE-17379] LSV-936: Stored XSS with a shared asset name in notification
A Cross-site scripting (XSS) vulnerability in the Sharing module’s user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
Details
**Type: ** Bug
Status: Closed
**Priority: ** Minor
Resolution: Fixed
Affects Version/s: 7.2 DXP (7.2.10)
- Component/s: None
CVSS Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
Cross-site scripting (XSS) vulnerability in the Sharing module’s user notification in Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload injected into the asset’s title text field.
Activity