Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
Critical severity
GitHub Reviewed
Published
Nov 15, 2022
to the GitHub Advisory Database
•
Updated Jul 16, 2025
Description
Published by the National Vulnerability Database
Nov 15, 2022
Published to the GitHub Advisory Database
Nov 15, 2022
Reviewed
Jul 16, 2025
Last updated
Jul 16, 2025
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the
title
field of a friendly URL.References