CVE-2025-43817Cross-site Scripting in Digital Experience Platform

Severity
4.8MEDIUMNVD
EPSS
0.0%
top 91.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateSep 30

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1) Announcements, or (2) Alerts.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.4.3.747.4.3.112
CVEListV5liferay/portal7.4.3.747.4.3.111
NVDliferay/digital_experience_platform2023.q3.12023.q3.9+2
CVEListV5liferay/dxp7.4.13-u747.4.13-u92+2

🔴Vulnerability Details

3
OSV
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter2025-09-30
GHSA
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter2025-09-30
CVEList
CVE-2025-43817: Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 72025-09-29

📋Vendor Advisories

1
Microsoft
net: missing check virtio2024-08-13
CVE-2025-43817 — Cross-site Scripting | cvebase