CVE-2025-43800: XSS
Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a rich text type field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43800?
CVE-2025-43800 has been classified as a medium severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-43800?
To mitigate CVE-2025-43800, upgrade to Liferay Portal version 7.4.3.112 or later and Liferay DXP 2023.Q3.5 or later.
What versions are affected by CVE-2025-43800?
CVE-2025-43800 affects Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP versions 2023.Q3.1 through 2023.Q3.4.
What are the risks associated with CVE-2025-43800?
Exploitation of CVE-2025-43800 can allow remote attackers to inject arbitrary web scripts or HTML, potentially compromising user security.
How can I confirm if my Liferay installation is vulnerable to CVE-2025-43800?
You can confirm vulnerability by checking the installed version of your Liferay Portal or Liferay DXP against the affected version range specified in CVE-2025-43800.