2.3
/ 10
LOW
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's name field. This malicious payload is then reflected and executed within the user's browser when viewing the "document View Usages" page.
Basic Information
ID
CVE-2025-43733
Source
Liferay
Published
Aug 18, 2025 at 12:06
Affected Product
Vendor
Liferay
Product
Portal
Version
7.4.3.132
Affected Versions
Liferay Portal 7.4.3.132
Liferay DXP 2025.Q1.0
Liferay DXP 2025.Q1.0