PT-2025-38092 · Liferay · Liferay Dxp+1

Published

2025-09-16

·

Updated

2025-09-17

·

CVE-2025-43804

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.93 through 7.4.3.111 Liferay DXP versions 2023.Q3.1 through 2023.Q3.4 Liferay DXP version 2023.Q4.0
Description A cross-site scripting (XSS) vulnerability exists in the Search widget. This allows remote attackers to inject arbitrary web script or HTML via the userId parameter.
Recommendations Liferay Portal versions 7.4.3.93 through 7.4.3.111: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q3.1 through 2023.Q3.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP version 2023.Q4.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43804
GHSA-CCRC-5VP5-VP5J

Affected Products

Liferay Dxp
Liferay Portal