A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-18T00:00:00

Updated: 2024-08-03T13:03:44.095Z

Reserved: 2022-10-03T00:00:00

Link: CVE-2022-42114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-18T21:15:16.287

Modified: 2022-10-20T18:09:39.217

Link: CVE-2022-42114

cve-icon Redhat

No data.