Lucene search

K
osvGoogleOSV:CVE-2022-26596
HistoryApr 25, 2022 - 4:16 p.m.

CVE-2022-26596

2022-04-2516:16:09
Google
osv.dev
8
cve-2022-26596
journal module
web content display
liferay portal
liferay dxp
remote attackers
web script
html
web content template names

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

42.6%

Cross-site scripting (XSS) vulnerability in Journal module’s web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.

References

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

42.6%

Related for OSV:CVE-2022-26596