Description
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
References
Vendor Advisory
https://issues.liferay.com/browse/LPE-17513
Issue TrackingVendor Advisory
Vendor Advisory
https://issues.liferay.com/browse/LPE-17513
Issue TrackingVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-15T01:15:12.733
3 years agoLast modified
2025-09-05T18:15:36.127
3 months ago