PT-2025-34503 · Liferay · Liferay Portal+1

Milcert At

·

Published

2025-08-23

·

Updated

2025-08-23

·

CVE-2025-43769

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.0 through 7.4.3.131 Liferay DXP versions 2024.Q1.1 through 2024.Q1.12 Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 Liferay DXP versions 2024.Q3.1 through 2024.Q3.8
Description: A stored cross-site scripting (XSS) vulnerability exists that allows remote attackers to execute arbitrary web script or HTML via the components tab.
Recommendations: Update Liferay Portal to a version later than 7.4.3.131. Update Liferay DXP to a version later than 2024.Q1.12. Update Liferay DXP to a version later than 2024.Q2.13. Update Liferay DXP to a version later than 2024.Q3.8.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43769
GHSA-RVMF-JW8G-R35R

Affected Products

Liferay Dxp
Liferay Portal