Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Assignee
EE SupportEE SupportReporter
Enterprise Release HUEnterprise Release HUPriority
Low
Details
Details
Assignee
EE Support
EE SupportReporter
Enterprise Release HU
Enterprise Release HUPriority
Zendesk Support
Zendesk Support
Zendesk Support
Created March 9, 2022 at 9:00 AM
Updated October 18, 2022 at 7:44 PM
Resolved October 18, 2022 at 7:44 PM
SQL injection vulnerability in the Fragment module's PortletPreferences upgrade process in Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.