A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-11-15T00:00:00
Updated: 2024-08-03T13:03:45.509Z
Reserved: 2022-10-03T00:00:00
Link: CVE-2022-42120
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-15T01:15:12.733
Modified: 2024-11-21T07:24:24.070
Link: CVE-2022-42120
Redhat
No data.