VYPR
Medium severity5.4NVD Advisory· Published Oct 13, 2022· Updated Jul 9, 2026

CVE-2022-38902

CVE-2022-38902

Description

A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • Liferay/DXP12 versions
    cpe:2.3:a:liferay:dxp:7.3:-:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:liferay:dxp:7.3:-:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:sp1:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:sp2:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:sp3:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_1:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_2:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_3:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_4:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_5:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_6:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_7:*:*:*:*:*:*
    • cpe:2.3:a:liferay:dxp:7.3:update_8:*:*:*:*:*:*
  • cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
    Range: >=7.3.0,<=7.4.0
  • (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 7.3.10 SP3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.