GHSA-fvg6-9r88-7w85

Suggest an improvement
Source
https://github.com/advisories/GHSA-fvg6-9r88-7w85
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fvg6-9r88-7w85/GHSA-fvg6-9r88-7w85.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fvg6-9r88-7w85
Aliases
Published
2022-05-24T19:10:01Z
Modified
2025-05-28T20:57:12.156310Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Details

Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the comliferayjournalwebportletJournalPortlet_name parameter.

Database specific
{
    "github_reviewed_at": "2025-05-28T20:14:38Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "nvd_published_at": "2021-08-04T13:15:00Z",
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

Maven / com.liferay.portal:release.portal.bom

Package

Name
com.liferay.portal:release.portal.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.portal.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.3.0
Fixed
7.3.4

Affected versions

7.*

7.3.0
7.3.0-1
7.3.1
7.3.1-1
7.3.2
7.3.2-1
7.3.3
7.3.3-1

Database specific

{
    "last_known_affected_version_range": "<= 7.3.3"
}

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.10.fp18

Affected versions

7.*

7.1.10
7.1.10.fp1
7.1.10.fp2
7.1.10.fp3
7.1.10.fp4
7.1.10.fp5
7.1.10.fp6
7.1.10.fp7
7.1.10.fp8
7.1.10.fp9
7.1.10.fp10
7.1.10.fp11
7.1.10.fp12
7.1.10.fp13
7.1.10.fp14
7.1.10.fp15
7.1.10.fp16
7.1.10.fp17

Maven / com.liferay.portal:release.dxp.bom

Package

Name
com.liferay.portal:release.dxp.bom
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/release.dxp.bom

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.2.10.fp5
Fixed
7.2.10.fp7

Affected versions

7.*

7.2.10.fp5
7.2.10.fp6