GHSA-7pxh-q6jw-6xj8

Suggest an improvement
Source
https://github.com/advisories/GHSA-7pxh-q6jw-6xj8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7pxh-q6jw-6xj8
Aliases
Published
2022-05-24T19:10:01Z
Modified
2025-05-28T20:57:12Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting
Details

Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-05-28T20:15:00Z",
    "nvd_published_at":  "2021-08-04T13:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.1
Fixed
7.3.5

Affected versions

7.*
7.2.1
7.2.1-1
7.3.0
7.3.0-1
7.3.1
7.3.1-1
7.3.2
7.3.2-1
7.3.3
7.3.3-1
7.3.4

Database specific

last_known_affected_version_range
"<= 7.3.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json"

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.10.fp9

Affected versions

7.*
7.2.1
7.2.10
7.2.10.fp1
7.2.10.fp1-1
7.2.10.fp2
7.2.10.fp3
7.2.10.fp4
7.2.10.fp5
7.2.10.fp6
7.2.10.fp7
7.2.10.fp8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7pxh-q6jw-6xj8/GHSA-7pxh-q6jw-6xj8.json"