CVE-2022-42122
CRITICALLiferay DXP 7.3.7 and 7.3.10.fp2-7.3.10.u3 - SQL Injection via Friendly URL Title Field
Title source: llmDescription
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
References (3)
Core 3
Core References
Vendor Advisory
http://liferay.com
Issue Tracking, Vendor Advisory
https://issues.liferay.com/browse/LPE-17520
Scores
CVSS v3
9.8
EPSS
0.0081
EPSS Percentile
74.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (5)
com.liferay/com.liferay.friendly.url.service
0 - 4.0.3Maven
com.liferay.portal/release.dxp.bom
7.3.10.fp2 - 7.3.10.u4Maven
com.liferay.portal/release.portal.bom
7.3.7 - 7.4.0-ga1Maven
liferay/dxp
7.3 fix_pack_2
liferay/liferay_portal
7.3.7
Published
Nov 15, 2022
Tracked Since
Feb 18, 2026