EXPOSURES › CVE-2022-42120
CVE-2022-42120
CRITICAL
DETAIL
SourceNVD · cve
Published2022-11-15
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-42120 ↗
⚡ RCE
SHAME 50/100
rce
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.