CVE-2022-42120

Description

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences namespace attribute.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.815

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Liferay - release.dxp.bom 7.3.10Windows
Vulnerabilities CVE-2022-42120,CVE-2022-42117 are fixed in Liferay - release.dxp.bom 7.4.13Windows
Vulnerabilities CVE-2022-42120 are fixed in Liferay - com.liferay.fragment.service 4.0.33Windows
Multiple vulnerabilities are fixed in Liferay - release.dxp.bom for Linux 7.3.10Linux
Vulnerabilities CVE-2022-42120,CVE-2022-42117 are fixed in Liferay - release.dxp.bom for Linux 7.4.13Linux
Vulnerabilities CVE-2022-42120 are fixed in Liferay - com.liferay.fragment.service for Linux 4.0.33Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234