{"id":"CVE-2022-38902","details":"A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.","modified":"2026-09-05T03:30:48.730100645Z","published":"2022-10-13T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38902.json"},"references":[{"type":"WEB","url":"https://drive.proton.me/urls/D27RQ14NGW#b71d8XrBl2Mu"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38902.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38902"},{"type":"ARTICLE","url":"https://www.offensity.com/en/blog/authenticated-persistent-xss-in-liferay-dxp-cms-cve-2022-38901-and-cve-2022-38902/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"b072f5df5544a28677824835b490ce8a867bf133"},{"last_affected":"ec84d86679146b84af526f96471a730c340dda78"}],"database_specific":{"extracted_events":[{"introduced":"7.3.0"},{"last_affected":"7.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*"}}],"versions":["7.4.0-ga1","7.3.5-ga6","7.3.4-ga5","test-fix-pack-base-7310","7.3.3-ga4","7.3.2-ga3","7.3.1-ga2","7.3.0-ga1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38902.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}