CVE-2025-43823: XSS
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43823?
CVE-2025-43823 is considered a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-43823?
To fix CVE-2025-43823, update to the latest patched version of Liferay Portal or Liferay DXP as specified by the vendor.
What products are affected by CVE-2025-43823?
CVE-2025-43823 affects Liferay Portal versions 7.4.0 to 7.4.3.111 and Liferay DXP versions before patch 6 for 2023.Q4 and before patch 9 for 2023.Q3.
Can CVE-2025-43823 be exploited remotely?
Yes, CVE-2025-43823 can be exploited remotely by attackers to inject arbitrary web script or HTML.
What is the impact of CVE-2025-43823?
The impact of CVE-2025-43823 includes potential unauthorized access and execution of malicious scripts on affected Liferay systems.