A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45207 | Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module |
Github GHSA |
GHSA-gxxj-fhmr-37j9 | Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay digital Experience Platform
|
|
| CPEs | cpe:2.3:a:liferay:dxp:7.1:fix_pack_10:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_11:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_12:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_13:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_14:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_15:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_16:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_17:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_18:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_19:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_20:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_21:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_22:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_23:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_24:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_25:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_7:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_8:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.1:fix_pack_9:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:-:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_10:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_11:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_12:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_13:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_14:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_15:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_7:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_8:*:*:*:*:*:* cpe:2.3:a:liferay:dxp:7.2:fix_pack_9:*:*:*:*:*:* |
cpe:2.3:a:liferay:digital_experience_platform:7.1:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_16:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_17:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_18:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_19:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_20:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_21:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_22:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_23:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_24:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_25:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.1:fix_pack_9:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_10:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_11:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_12:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_13:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_15:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_3:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_4:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_6:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_7:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_9:*:*:*:*:*:* |
| Vendors & Products |
Liferay digital Experience Platform
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-05T17:25:54.666Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42121
Updated: 2024-08-03T13:03:45.532Z
Status : Modified
Published: 2022-11-15T01:15:12.843
Modified: 2025-09-05T18:15:36.413
Link: CVE-2022-42121
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA