VYPR

Maven package

com.liferay/com.liferay.asset.taglib

pkg:maven/com.liferay/com.liferay.asset.taglib

Vulnerabilities (2)

  • CVE-2022-28982Sep 21, 2022
    affected < 6.1.9fixed 6.1.9

    A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.

  • CVE-2022-26593Apr 19, 2022
    affected < 6.1.0fixed 6.1.0

    Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.