Critical severity9.8NVD Advisory· Published Nov 15, 2022· Updated Jun 17, 2026
CVE-2022-42122
CVE-2022-42122
Description
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the title field of a friendly URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | >= 7.3.7, < 7.4.0-ga1 | 7.4.0-ga1 |
com.liferay.portal:release.dxp.bomMaven | >= 7.3.10.fp2, < 7.3.10.u4 | 7.3.10.u4 |
com.liferay:com.liferay.friendly.url.serviceMaven | < 4.0.3 | 4.0.3 |
Affected products
4- Liferay/Friendly Url module in Portaldescription
- ghsa-coords3 versionspkg:maven/com.liferay/com.liferay.friendly.url.servicepkg:maven/com.liferay.portal/release.dxp.bompkg:maven/com.liferay.portal/release.portal.bom
< 4.0.3+ 2 more
- (no CPE)range: < 4.0.3
- (no CPE)range: >= 7.3.10.fp2, < 7.3.10.u4
- (no CPE)range: >= 7.3.7, < 7.4.0-ga1
Patches
Vulnerability mechanics
References
7- liferay.comnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-hw56-7xj4-7gx6ghsaADVISORY
- issues.liferay.com/browse/LPE-17520nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42122ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42122nvdVendor AdvisoryWEB
- liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-42122ghsaWEB
- web.archive.org/web/20221115051621/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42122ghsaWEB
News mentions
0No linked articles in our index yet.