Liferay DXP 7.3 Fix Pack 2

CPE Details

Liferay DXP 7.3 Fix Pack 2
7.3
2022-11-15
18h39 +00:00
2022-11-29
13h20 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:liferay:dxp:7.3:fix_pack_2:*:*:*:*:*:*

Informations

Vendor

liferay

Product

dxp

Version

7.3

Update

fix_pack_2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-25145 2024-02-07 14h57 +00:00 Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
9.6
Critique
CVE-2022-42122 2022-11-14 23h00 +00:00 A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
9.8
Critique
CVE-2022-42114 2022-10-17 22h00 +00:00 A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
5.4
Moyen
CVE-2022-42117 2022-10-17 22h00 +00:00 A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
6.1
Moyen