CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-42120

Critical · CVSS 9.8

Liferay Portal / Liferay DXP Fragment Module — SQL Injection via PortletPreferences namespace attribute

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-89, CWE-89

Description

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

Search profile — drives PoC discovery

Symbols namespacePortletPreferencescom.liferay.fragment.serviceFragmentServicerelease.dxp.bomLPE-17513
Keywords CVE-2022-42120Liferay Portal SQL injectionLiferay DXP Fragment module SQLiPortletPreferences namespace SQL injectioncom.liferay.fragment.service exploitLiferay 7.3 7.4 SQLi PoCLPE-17513
Versions: Liferay Portal 7.3.3 through 7.4.3.16; Liferay DXP 7.3 before update 4; Liferay DXP 7.4 before update 17

Affected packages

Maven com.liferay.portal:release.dxp.bom 7.3.0 → 7.3.10.u4
Maven com.liferay.portal:release.dxp.bom 7.4.0 → 7.4.13.u17
Maven com.liferay:com.liferay.fragment.service 0 → 4.0.33

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z