Cross-site Scripting Flaw in Liferay Portal and DXP Products
CVE-2025-43804
What is CVE-2025-43804?
A Cross-site scripting (XSS) vulnerability exists in the Search widget of Liferay Portal versions 7.4.3.93 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4. This vulnerability enables remote attackers to exploit the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter, allowing the injection of arbitrary web scripts or HTML. Successful exploitation could lead to unauthorized actions being performed on behalf of a user, compromising the security of the affected application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 2023.Q3.1 <= 2023.Q3.4
DXP 2023.Q4.0 <= 2023.Q4.1
Portal 7.4.3.93 <= 7.4.3.111
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved