CVE-2025-43785: XSS
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.portal.workflow.task.webto a version that resolves this vulnerability.Fixed in 5.0.75 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 2024.Q1.13 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 2024.Q3.0 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.129
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43785?
CVE-2025-43785 is classified as a medium-severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43785?
To fix CVE-2025-43785, upgrade Liferay Portal to version 7.4.3.129 or later and Liferay DXP to the latest recommended version.
Who is affected by CVE-2025-43785?
CVE-2025-43785 affects Liferay Portal versions between 7.4.3.45 and 7.4.3.128 and several versions of Liferay DXP.
What systems are vulnerable to CVE-2025-43785?
Systems utilizing Liferay Portal 7.4.3.45 through 7.4.3.128 and Liferay DXP 2024 Q1.1 through Q2.9 are vulnerable to CVE-2025-43785.
What can attackers do with CVE-2025-43785?
Attackers exploiting CVE-2025-43785 can execute arbitrary web scripts or HTML on the vulnerable Liferay platforms.