PT-2025-37774 · Liferay · Liferay Portal+1

Amin Achour

·

Published

2025-09-15

·

Updated

2025-09-16

·

CVE-2025-43802

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.51 through 7.4.3.109 Liferay DXP versions 2023.Q3.1 through 2023.Q3.4 Liferay DXP 7.4 update 51 through update 92 Liferay DXP 7.3 update 33 through update 35
Description A stored cross-site scripting (XSS) vulnerability exists in a custom object’s /o/c/<object-name> API endpoint. This allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter.
Recommendations Liferay Portal versions 7.4.3.51 through 7.4.3.109: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q3.1 through 2023.Q3.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP 7.4 update 51 through update 92: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP 7.3 update 33 through update 35: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43802
GHSA-VG6H-G5MR-9HGV

Affected Products

Liferay Dxp
Liferay Portal