CVE-2022-42118
Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
Record summary
CVE-2022-42118 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
com.liferay.portal:release.dxp.bomBrowse Maven / com.liferay.portal:release.dxp.bom | GitHub Advisory | 7.1.0 to < 7.1.10.fp27 · Fixed in 7.1.10.fp27 | affected |
| 7.2.0 to < 7.2.10.fp15 · Fixed in 7.2.10.fp15 | affected | ||
com.liferay:com.liferay.portal.search.webBrowse Maven / com.liferay:com.liferay.portal.search.web | GitHub Advisory | Before 6.0.12 · Fixed in 6.0.12 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLiferay Portal - Cross-site ScriptingCVSS 6.1
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
Impact
Unauthenticated attackers can inject malicious JavaScript through the tag parameter in the Portal Search module to steal Liferay Portal user session cookies and credentials.
Remediation
Update to Liferay Portal 7.4.3+, DXP 7.1 fix pack 27+, DXP 7.2 fix pack 15+, or DXP 7.3 service pack 3+.
Source: ProjectDiscovery