← Back to CVE List

CVE-2022-42110

Published: 2022-11-15T00:15Z
Last Modified: 2024-11-21T07:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt