216.73.217.80

CVE-2025-43779

· Published 24/09/2025 01:15 · Modified 24/09/2025 18:11

Labels: CVE-2025-43779 2025-09-24CVE-2025-43779CWE-79[email protected]

Essential information

Published
24/09/2025 01:15
Modified
24/09/2025 18:11
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName parameter. This malicious payload is then reflected and executed within the user's browser.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
liferay / liferay portal cpe:2.3:a:liferay:liferay_portal:7.4.0-7.4.3.112:*:*:*:*:*:*:*
liferay / liferay dxp cpe:2.3:a:liferay:liferay_dxp:2024.Q1.1-2024.Q1.18:*:*:*:*:*:*:*
liferay / liferay portal cpe:2.3:a:liferay:liferay_portal:7.4:*:*:*:*:*:*:*

References