CVE-2025-43733: XSS
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's name field. This malicious payload is then reflected and executed within the user's browser when viewing the "document View Usages" page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43733?
CVE-2025-43733 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43733?
To fix CVE-2025-43733, ensure you upgrade to Liferay Portal 7.4.3.133 or a later version, or Liferay DXP 2025.Q1.8 or a later version.
Who is affected by CVE-2025-43733?
CVE-2025-43733 affects users of Liferay Portal version 7.4.3.132 and Liferay DXP versions 2025.Q1.0 through 2025.Q1.7.
What can an attacker do with CVE-2025-43733?
An attacker can exploit CVE-2025-43733 to inject and execute JavaScript code within the user's browser session.
Is user authentication required to exploit CVE-2025-43733?
Yes, CVE-2025-43733 requires an authenticated user to exploit the vulnerability.