CVE-2022-38902

Source
https://cve.org/CVERecord?id=CVE-2022-38902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-38902
Published
2022-10-13T13:15:10.043Z
Modified
2026-04-10T04:52:30.969102Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.

References

Affected packages

Git / github.com/liferay/liferay-portal

Affected ranges

Type
GIT
Repo
https://github.com/liferay/liferay-portal
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-sp1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-sp2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-sp3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.3-update_7"
        },
        {
            "introduced": "7.3.0"
        },
        {
            "last_affected": "7.4.0"
        }
    ]
}

Affected versions

7.*
7.3.0-ga1
7.3.1-ga2
7.3.2-ga3
7.3.3-ga4
7.3.4-ga5
7.3.5-ga6
7.3.6-ga7
7.3.7-ga8
7.4.0-ga1
Other
test-fix-pack-base-7310

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38902.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.3-NA"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.3-update_8"
            }
        ]
    }
]