CVE-2022-42121 Information

Description

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4 and Liferay DXP 7.1 before fix pack 27 7.2 before fix pack 17 7.3 before service pack 3 and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template’s ‘Name’ field.

Reference

http://liferay.com https://issues.liferay.com/browse/LPE-17414 https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42121

Share on: