cbcvebase.
CVE-2025-43735
published 2025-08-12

CVE-2025-43735: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1…

medium6.9CVSS 4.0
AVNACLATNPRNUINVCLVILVANSCLSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.

Affected

12 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydigital_experience_platform2024.q1.1 – 2024.q1.12
liferaydigital_experience_platform2024.q2.0 – 2024.q2.13
liferaydigital_experience_platform2024.q3.1 – 2024.q3.13
liferaydigital_experience_platform2024.q4.0 – 2024.q4.7
liferaydxp2024.Q1.1 – 2024.Q1.12
liferaydxp2024.Q2.0 – 2024.Q2.13
liferaydxp2024.Q3.1 – 2024.Q3.13
liferaydxp2024.Q4.0 – 2024.Q4.7
liferaydxp7.4.13 – 7.4.13-u92
liferayliferay_portal7.4.0 – 7.4.3.131
liferayportal7.4.0 – 7.4.3.131