MEDIUM
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module
Published Nov 15, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.42%
Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Affected products
No data.
Configuration 1
- ≥ 7.3.5 · ≤ 7.4.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://liferay.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45205 Advisory
- https://github.com/advisories/GHSA-wjfm-qxg2-q679 Advisory
- https://github.com/liferay/liferay-portal/commit/2e02110747dd5cccb978623545bfa1f3ad0a5602
- https://issues.liferay.com/browse/LPE-17632 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-42119
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119 Vendor Advisory
- https://web.archive.org/web/20221115040019/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 15, 2022
Updated Jul 9, 2026
Reserved Oct 3, 2022
Link CVE-2022-42119
CISA Vulnrichment
Updated Apr 30, 2025
ENISA EUVD
EUVD-2022-45205 GHSA-WJFM-QXG2-Q679 Assigner mitre
Published Nov 15, 2022
Updated Jul 9, 2026
Exploited since n/a
Link EUVD-2022-45205