CVE-2025-43738: XSS
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 allows a remote authenticated user to inject JavaScript code via comliferayexpandowebportletExpandoPortletdisplayType parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43738?
CVE-2025-43738 has been classified as a medium severity reflected cross-site scripting vulnerability.
How do I fix CVE-2025-43738?
To fix CVE-2025-43738, update Liferay Portal to version 7.4.3.133 or later and Liferay DXP to the latest available release.
Which versions are affected by CVE-2025-43738?
CVE-2025-43738 affects Liferay Portal versions 7.4.0 to 7.4.3.132 and various Liferay DXP versions from 2024.Q1.0 to 2025.Q2.8.
What is the impact of CVE-2025-43738?
The impact of CVE-2025-43738 includes the potential for an attacker to execute arbitrary JavaScript code in the context of the user's browser.
Is authentication required to exploit CVE-2025-43738?
No, CVE-2025-43738 can be exploited without authentication, allowing unauthenticated attackers to execute the attack.