CVE-2025-43811: XSS
Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected into an asset author’s (1) First Name, (2) Middle Name, or (3) Last Name text field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43811?
CVE-2025-43811 is rated as a medium severity vulnerability due to its potential to allow remote authenticated attackers to execute stored cross-site scripting attacks.
How do I fix CVE-2025-43811?
To mitigate CVE-2025-43811, upgrade your Liferay Portal or Liferay DXP instance to the latest patched version that addresses this vulnerability.
What software versions are affected by CVE-2025-43811?
CVE-2025-43811 affects Liferay Portal versions 7.4.3.50 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.4, among others.
Who can exploit CVE-2025-43811?
CVE-2025-43811 can be exploited by remote authenticated attackers who have access to the related asset selector functionality.
What types of attacks can CVE-2025-43811 facilitate?
CVE-2025-43811 can facilitate stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the affected application.