CVE-2025-43734: XSS
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code in the “first display label” field in the configuration of a custom sort widget. This malicious payload is then reflected and executed by clay button taglib when refreshing the page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43734?
CVE-2025-43734 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43734?
To fix CVE-2025-43734, you should update Liferay Portal to version 7.4.3.133 or later, and Liferay DXP to the subsequent patched versions.
What versions are affected by CVE-2025-43734?
CVE-2025-43734 affects Liferay Portal versions 7.4.0 to 7.4.3.132 and Liferay DXP versions from 2025.Q1.0 through 2025.Q1.10 and earlier releases of 2024 versions.
What type of vulnerability is CVE-2025-43734?
CVE-2025-43734 is a reflected cross-site scripting (XSS) vulnerability which can allow an attacker to inject malicious scripts.
Can CVE-2025-43734 be exploited remotely?
Yes, CVE-2025-43734 can be exploited remotely if an attacker tricks a user into clicking a specially crafted link.