Vulnerability Details CVE-2022-42122
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-42122
-
cpe:2.3:a:liferay:dxp:7.3
-
cpe:2.3:a:liferay:liferay_portal:7.3.7