PT-2025-41253 · Liferay · Liferay Portal+1

Foobar7

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-43821

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.0 through 7.4.3.111 Liferay DXP versions 2023.Q3.1 through 2023.Q3.8 Liferay DXP versions 2023.Q4.0 through 2023.Q4.5
Description A cross-site scripting (XSS) issue exists in the Commerce Product Comparison Table widget. This allows remote attackers to inject arbitrary web script or HTML through a crafted payload. The payload is injected into the Commerce Product's Name text field.
Recommendations Liferay Portal versions 7.4.0 through 7.4.3.111 should be updated. Liferay DXP versions 2023.Q3.1 through 2023.Q3.8 should be updated. Liferay DXP versions 2023.Q4.0 through 2023.Q4.5 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43821
GHSA-FJRP-77F3-43XJ

Affected Products

Liferay Dxp
Liferay Portal