A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-18T00:00:00

Updated: 2024-08-03T13:03:45.182Z

Reserved: 2022-10-03T00:00:00

Link: CVE-2022-42113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-18T21:15:16.247

Modified: 2022-10-20T18:34:50.663

Link: CVE-2022-42113

cve-icon Redhat

No data.