CVE-2022-42121
HIGHLiferay Portal 7.1.3-7.4.3.4 and DXP - Authenticated SQL Injection via Page Template Name Field
Title source: llmDescription
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
References (3)
Core 3
Core References
Vendor Advisory
http://liferay.com
Issue Tracking, Vendor Advisory
https://issues.liferay.com/browse/LPE-17414
Scores
CVSS v3
8.8
EPSS
0.0060
EPSS Percentile
69.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (7)
com.liferay/com.liferay.layout.page.template.service
0 - 4.0.17Maven
com.liferay.portal/release.dxp.bom
7.1.0 - 7.1.10.fp27Maven
liferay/digital_experience_platform
7.1 (26 CPE variants)
liferay/digital_experience_platform
7.2 (16 CPE variants)
liferay/dxp
7.3 (3 CPE variants)
liferay/dxp
7.4 ga1
liferay/liferay_portal
7.1.3 - 7.4.3.4
Published
Nov 15, 2022
Tracked Since
Feb 18, 2026