CVE-2025-43781: XSS
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43781?
CVE-2025-43781 is categorized as a critical reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43781?
To fix CVE-2025-43781, upgrade Liferay Portal to version 7.4.3.129 or later, or upgrade Liferay DXP to the latest recommended release.
What versions are affected by CVE-2025-43781?
CVE-2025-43781 affects Liferay Portal versions 7.4.3.110 to 7.4.3.128 and Liferay DXP versions from 2024.Q1.1 to 2024.Q3.8.
Can CVE-2025-43781 be exploited remotely?
Yes, CVE-2025-43781 can be exploited remotely by attackers through manipulated URL parameters.
What type of vulnerability is CVE-2025-43781?
CVE-2025-43781 is a reflected cross-site scripting (XSS) vulnerability that allows injection of arbitrary scripts or HTML.