CVE-2022-26594 – com.liferay:com.liferay.dynamic.data.mapping.form.field.type
Package
Manager: maven
Name: com.liferay:com.liferay.dynamic.data.mapping.form.field.type
Vulnerable Version: >=0 <6.0.11
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00257 pctl0.48895
Details
Liferay Portal and Liferay DXP allows arbitrary injection via form field Multiple cross-site scripting (XSS) vulnerabilities in Dynamic Data Mapping Form Field Type before 6.0.11 from Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
Metadata
Created: 2022-04-16T00:00:47Z
Modified: 2025-07-14T21:45:16Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-658f-xhv4-p978/GHSA-658f-xhv4-p978.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-658f-xhv4-p978
Finding: F425
Auto approve: 1