CVE-2022-42120
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL w module Fragment Liferay Portal umożliwia wykonanie dowolnych poleceń SQL.
CVSS
9.8
EPSS
0.7%
Exploit
none
Vendor
liferay
Opis źródłowy (NVD)
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.7% |
| Opublikowano (NVD) | 2022-11-15 01:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 01:17:47 UTC |
Referencje
- https://issues.liferay.com/browse/LPE-17513 (cve@mitre.org) [Issue Tracking, Vendor Advisory]
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42120 (cve@mitre.org) [Vendor Advisory]