CVE-2022-38902

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-38902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-38902
Published
2022-10-13T13:15:10Z
Modified
2025-05-15T20:38:25.213763Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.

References

Affected packages

Git / github.com/liferay/liferay-portal

Affected versions

7.*

7.3.0-ga1
7.3.1-ga2
7.3.2-ga3