A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.4-ga1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4-update_2"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.3.37"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_36"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-42114.json"