CVE-2025-43815: XSS
Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML via the comliferaylayoutadminwebportletGroupPagesPortletbackURLTitle parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43815?
CVE-2025-43815 is rated as a high-severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43815?
To fix CVE-2025-43815, upgrade Liferay Portal to version 7.4.3.111 or later and Liferay DXP to version 2023.Q4.3 or later.
What platforms are affected by CVE-2025-43815?
CVE-2025-43815 affects Liferay Portal versions 7.4.3.102 to 7.4.3.110 and Liferay DXP versions 2023.Q4.0 to 2023.Q4.2.
What type of vulnerability is CVE-2025-43815?
CVE-2025-43815 is a reflected cross-site scripting (XSS) vulnerability.
Is CVE-2025-43815 exploitable remotely?
Yes, CVE-2025-43815 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.