CVE-2022-42120
Critical · CVSS 9.8Liferay Portal / Liferay DXP Fragment Module — SQL Injection via PortletPreferences namespace attribute
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-89, CWE-89
Description
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
Search profile — drives PoC discovery
Symbols namespacePortletPreferencescom.liferay.fragment.serviceFragmentServicerelease.dxp.bomLPE-17513
Keywords CVE-2022-42120Liferay Portal SQL injectionLiferay DXP Fragment module SQLiPortletPreferences namespace SQL injectioncom.liferay.fragment.service exploitLiferay 7.3 7.4 SQLi PoCLPE-17513
Versions: Liferay Portal 7.3.3 through 7.4.3.16; Liferay DXP 7.3 before update 4; Liferay DXP 7.4 before update 17
Affected packages
| Maven | com.liferay.portal:release.dxp.bom | 7.3.0 → 7.3.10.u4 |
| Maven | com.liferay.portal:release.dxp.bom | 7.4.0 → 7.4.13.u17 |
| Maven | com.liferay:com.liferay.fragment.service | 0 → 4.0.33 |
References
- https://issues.liferay.com/browse/LPE-17513
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42120
- http://liferay.com
- https://issues.liferay.com/browse/LPE-17513
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42120
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z