CVE-2025-43779: XSS
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via comliferaycommerceproductdefinitionswebinternalportletCPDefinitionsPortletproductTypeName parameter. This malicious payload is then reflected and executed within the user's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43779?
CVE-2025-43779 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43779?
To mitigate CVE-2025-43779, it's crucial to upgrade Liferay Portal to version 7.4.3.113 or later and Liferay DXP to version 2024.Q1.19 or later.
Who is affected by CVE-2025-43779?
CVE-2025-43779 affects Liferay Portal versions 7.4.0 through 7.4.3.112 and Liferay DXP versions 2024.Q1.1 through 2024.Q1.18.
What causes CVE-2025-43779?
CVE-2025-43779 is caused by a flaw that allows remote authenticated attackers to inject JavaScript code via specific web requests.
What should I do if I am using an affected version for CVE-2025-43779?
If using an affected version for CVE-2025-43779, immediately upgrade to the latest patched version to prevent potential exploitation.