CVE-2025-43783: XSS
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 update 73 through update 92 allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/geteditor path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43783?
CVE-2025-43783 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43783?
To fix CVE-2025-43783, update Liferay Portal to version 7.4.3.129 or higher, and Liferay DXP to version 2024.Q3.2 or higher.
What versions are affected by CVE-2025-43783?
CVE-2025-43783 affects Liferay Portal versions 7.4.3.73 through 7.4.3.128 and Liferay DXP versions from 2024.Q1.1 through 2024.Q3.1.
Can CVE-2025-43783 be exploited remotely?
Yes, CVE-2025-43783 can be exploited by remote attackers to inject arbitrary web scripts or HTML.
What is the potential impact of CVE-2025-43783?
The potential impact of CVE-2025-43783 includes unauthorized access to user data and potential site defacement due to XSS attacks.