CVE-2022-28982

MEDIUM

Liferay DXP 7.3.3-7.4.2 and Liferay Portal 7.3.3-7.4.2 - Stored Cross-Site Scripting via Asset Tag Name

Title source: llm
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.

Scores

CVSS v3 6.1
EPSS 0.0040
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
com.liferay/com.liferay.asset.taglib 0 - 6.1.9Maven
liferay/dxp 7.3 (4 CPE variants)
liferay/liferay_portal 7.3.3 - 7.4.3.4
Published Sep 22, 2022
Tracked Since Feb 18, 2026