Skip to main content

CVE-2025-43760: CWE-79: Cross-site Scripting in Liferay Portal

Medium
VulnerabilityCVE-2025-43760cvecve-2025-43760cwe-79
Published: Fri Aug 22 2025 (08/22/2025, 17:34:51 UTC)
Source: CVE Database V5
Vendor/Project: Liferay
Product: Portal

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScript into the PortalUtil.escapeRedirect

Technical Details

Data Version
5.1
Assigner Short Name
Liferay
Date Reserved
2025-04-17T10:55:24.866Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68a8ad43ad5a09ad0020e5ce

Added to database: 8/22/2025, 5:47:47 PM

Last updated: 8/22/2025, 5:47:47 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats