CVE-2022-42120
n/a n/a, dxp, liferay portal 취약점
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
- 대응 우선순위
- 점검
- CVSS
- 9.8
- EPSS
- 0.73% 백분위 50.7% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2022.11.15