CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-42122

Critical · CVSS 9.8

Liferay Portal / Liferay DXP - Friendly URL module — SQL Injection (CWE-89) via Friendly URL title field

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-89, CWE-89

Description

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.

Search profile — drives PoC discovery

Symbols com.liferay.friendly.url.servicerelease.dxp.bomrelease.portal.bomtitleFriendlyURLFriendlyURLEntryFriendlyURLLocalServiceFriendlyURLServiceLPE-17520
Keywords CVE-2022-42122Liferay Portal SQL injectionLiferay DXP Friendly URL SQLiLiferay friendly URL title SQL injectionLPE-17520com.liferay.friendly.url.service exploitLiferay 7.3.7 SQLi PoCLiferay DXP 7.3 SQL injection proof of concept
Versions: Liferay Portal 7.3.7; Liferay DXP 7.3 fix pack 2 through update 4

Affected packages

Maven com.liferay.portal:release.dxp.bom 7.3.10.fp2 → 7.3.10.u4
Maven com.liferay.portal:release.portal.bom 7.3.7 → 7.4.0-ga1
Maven com.liferay:com.liferay.friendly.url.service 0 → 4.0.3

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z