CVE-2022-42122
Critical · CVSS 9.8Liferay Portal / Liferay DXP - Friendly URL module — SQL Injection (CWE-89) via Friendly URL title field
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-89, CWE-89
Description
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
Search profile — drives PoC discovery
Symbols com.liferay.friendly.url.servicerelease.dxp.bomrelease.portal.bomtitleFriendlyURLFriendlyURLEntryFriendlyURLLocalServiceFriendlyURLServiceLPE-17520
Keywords CVE-2022-42122Liferay Portal SQL injectionLiferay DXP Friendly URL SQLiLiferay friendly URL title SQL injectionLPE-17520com.liferay.friendly.url.service exploitLiferay 7.3.7 SQLi PoCLiferay DXP 7.3 SQL injection proof of concept
Versions: Liferay Portal 7.3.7; Liferay DXP 7.3 fix pack 2 through update 4
Affected packages
| Maven | com.liferay.portal:release.dxp.bom | 7.3.10.fp2 → 7.3.10.u4 |
| Maven | com.liferay.portal:release.portal.bom | 7.3.7 → 7.4.0-ga1 |
| Maven | com.liferay:com.liferay.friendly.url.service | 0 → 4.0.3 |
References
- https://issues.liferay.com/browse/LPE-17520
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42122
- http://liferay.com
- https://issues.liferay.com/browse/LPE-17520
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42122
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z