Skip to content
COOEY

EXPOSURES › CVE-2022-42120

CVE-2022-42120

CRITICAL
DETAIL
SourceNVD · cve Published2022-11-15 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-42120 ↗
⚡ RCE SHAME 50/100 rce

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.