Vulnerabilities > Liferay > Digital Experience Platform > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-42131 Improper Certificate Validation vulnerability in Liferay Digital Experience Platform and Liferay Portal
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers.
network
high complexity
liferay CWE-295
4.8
2022-11-15 CVE-2022-42132 Information Exposure vulnerability in Liferay Digital Experience Platform 7.0/7.1/7.2
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
network
high complexity
liferay CWE-200
5.9
2022-11-15 CVE-2022-42126 Unspecified vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
network
low complexity
liferay
4.3
2022-11-15 CVE-2022-42127 Incorrect Default Permissions vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
network
low complexity
liferay CWE-276
5.3
2022-11-15 CVE-2022-42128 Incorrect Default Permissions vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
network
low complexity
liferay CWE-276
5.3
2022-04-25 CVE-2022-26596 Cross-site Scripting vulnerability in Liferay Digital Experience Platform 7.0/7.1/7.2
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
network
low complexity
liferay CWE-79
6.1
2022-04-25 CVE-2022-26597 Cross-site Scripting vulnerability in Liferay Digital Experience Platform 7.0/7.3
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
network
low complexity
liferay CWE-79
6.1
2022-04-19 CVE-2022-26593 Cross-site Scripting vulnerability in Liferay Digital Experience Platform and Liferay Portal
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
network
low complexity
liferay CWE-79
5.4
2022-04-19 CVE-2022-26595 Incorrect Default Permissions vulnerability in Liferay Digital Experience Platform and Liferay Portal
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
network
low complexity
liferay CWE-276
4.3
2022-03-03 CVE-2021-38263 Cross-site Scripting vulnerability in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
network
low complexity
liferay CWE-79
6.1