CVE 5.1 MEDIUM

CVE-2025-43815_CVE-2025-43815

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML via the com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURLTitle parameter.

Basic Information

ID CVE-2025-43815
Source Liferay
Published Sep 29, 2025 at 21:19

Affected Product

Vendor Liferay
Product Portal
Version 7.4.3.102
Affected Versions Liferay Portal 7.4.3.102
Liferay DXP 2023.Q3.5
Liferay DXP 2023.Q4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.