PT-2025-37067 · Liferay · Liferay+2

Published

2025-09-10

·

Updated

2025-12-16

·

CVE-2025-43785

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.3.45 through 7.4.3.128 Liferay DXP versions 2024 Q1.1 through 2024.Q1.12 Liferay DXP versions 2024 Q2.0 through 2024.Q2.9 Liferay versions 7.4 update 45 through update 92
Description: A stored cross-site scripting (XSS) vulnerability exists in Liferay Portal and DXP. This vulnerability allows remote attackers to execute arbitrary web scripts or HTML within the My Workflow Tasks page.
Recommendations: Update Liferay Portal to a version later than 7.4.3.128. Update Liferay DXP to a version later than 2024.Q2.9. Update Liferay DXP to a version later than 2024.Q1.12. Update Liferay to a version later than update 92.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43785
GHSA-66X6-8JGV-QPFH

Affected Products

Liferay
Liferay Dxp
Liferay Portal