Record summary

CVE-2022-42118 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

com.liferay.portal:release.dxp.bom

Browse Maven / com.liferay.portal:release.dxp.bom
GitHub Advisory7.1.0 to < 7.1.10.fp27 · Fixed in 7.1.10.fp27affected
7.2.0 to < 7.2.10.fp15 · Fixed in 7.2.10.fp15affected

com.liferay:com.liferay.portal.search.web

Browse Maven / com.liferay:com.liferay.portal.search.web
GitHub AdvisoryBefore 6.0.12 · Fixed in 6.0.12affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLiferay Portal - Cross-site ScriptingCVSS 6.1

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.

Impact

Unauthenticated attackers can inject malicious JavaScript through the tag parameter in the Portal Search module to steal Liferay Portal user session cookies and credentials.

Remediation

Update to Liferay Portal 7.4.3+, DXP 7.1 fix pack 27+, DXP 7.2 fix pack 15+, or DXP 7.3 service pack 3+.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2022liferayxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Shodan: html:"var Liferay"
FOFA: body="var Liferay"

Source: ProjectDiscovery

References

7
liferay.dev
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-42118?p_r_p_assetEntryId=121613298&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121613298%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse