Beveiligingsadvies

CVE-2022-26596

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-04-25 15:41:28
Laatst bijgewerkt 2026-07-09 00:18:02
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.