CVE-2025-43735Cross-site Scripting in DXP

Severity
6.9MEDIUMNVD
EPSS
0.0%
top 93.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Packages4 packages

CVEListV5liferay/portal7.4.07.4.3.131
NVDliferay/liferay_portal7.4.07.4.3.131
CVEListV5liferay/dxp7.4.137.4.13-u92+4
NVDliferay/digital_experience_platform2024.q1.12024.q1.12+4

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability2025-08-12
CVEList
CVE-2025-43735: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 72025-08-12
GHSA
Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability2025-08-12
CVE-2025-43735 — Cross-site Scripting in Liferay DXP | cvebase