Description


A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

Related CPE's


a

liferay

dxp

2

Weaknesses



CWE-89

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-15T00:15:12.733Z

3 years ago

Last modified

2025-09-05T16:15:36.127Z

6 months ago