PT-2025-39907 · Liferay · Liferay Portal+1

Argon21

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-43812

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.4 through 7.4.3.111 Liferay DXP versions 2023.Q3.1 through 2023.Q3.8 Liferay DXP versions 2023.Q4.0 through 2023.Q4.4
Description A cross-site scripting (XSS) issue exists in the web content template functionality. This allows a remote authenticated user to inject arbitrary web script or HTML. The injection occurs through a crafted payload within the Name text field of a web content structure.
Recommendations Update Liferay Portal to a version later than 7.4.3.111. Update Liferay DXP to a version later than 2023.Q3.8. Update Liferay DXP to a version later than 2023.Q4.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43812
GHSA-JV8X-MM3V-75R7

Affected Products

Liferay Dxp
Liferay Portal