← Back to CVE List

CVE-2022-42118

Published: 2022-11-15T01:15Z
Last Modified: 2024-11-21T07:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt