Liferay Portal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2022-42121 - Vulnerability Database

Liferay Portal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2022-42121

High
Reference: CVE-2022-42121
Title: Liferay Portal Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4 and Liferay DXP 7.1 before fix pack 27 7.2 before fix pack 17 7.3 before service pack 3 and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template39s 39Name39 field.