CVE-2025-43731
Essential information
- Published
- 18/08/2025 19:15
- Modified
- 18/08/2025 20:16
- Author
- —
- Creator
- —
- CVSS
- 6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
- CISA KEV
- No
- CWE
- —
- CVSS vector
-
—
—
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS metrics
- Access vector
- —
- Access complexity
- —
- Authentication
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Privileges required
- —
- User interaction
- —
- Scope
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- NETWORK
- Attack complexity
- LOW
- Attack requirements
- NONE
- Privileges required
- NONE
- User interaction
- NONE
- Confidentiality (V)
- LOW
- Confidentiality (S)
- LOW
- Integrity (V)
- LOW
- Integrity (S)
- LOW
- Availability (V)
- NONE
- Availability (S)
- NONE
- Exploit maturity
- NOT_DEFINED
Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows an remote authenticated user to inject JavaScript in message board threads and categories.
NVD status
- Status
- Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| liferay / liferay portal | cpe:2.3:a:liferay:liferay_portal:7.4.0-7.4.3.132:*:*:*:*:*:*:* |
| liferay / liferay dxp | cpe:2.3:a:liferay:liferay_dxp:2025.Q1.0-2025.Q1.8:*:*:*:*:*:*:* |
| liferay / liferay dxp | cpe:2.3:a:liferay:liferay_dxp:2024.Q4.0-2024.Q4.7:*:*:*:*:*:*:* |
| liferay / liferay dxp | cpe:2.3:a:liferay:liferay_dxp:2024.Q3.1-2024.Q3.13:*:*:*:*:*:*:* |
| liferay / liferay dxp | cpe:2.3:a:liferay:liferay_dxp:2024.Q2.0-2024.Q2.13:*:*:*:*:*:*:* |
| liferay / liferay dxp | cpe:2.3:a:liferay:liferay_dxp:2024.Q1.1-2024.Q1.16:*:*:*:*:*:*:* |
| liferay / liferay portal | cpe:2.3:a:liferay:liferay_portal:7.4:GA:update:92:*:*:*:*:*:* |