A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.3-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_3"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_4"
},
{
"introduced": "0"
},
{
"last_affected": "7.3-update_5"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_2"
},
{
"introduced": "7.3.5"
},
{
"last_affected": "7.4.3.28"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38901.json"
[
{
"events": [
{
"introduced": "7.0"
},
{
"fixed": "7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_9"
}
]
}
]