Stored Cross-Site Scripting Vulnerability in Liferay Portal and DXP
CVE-2025-43830
5.1MEDIUM
What is CVE-2025-43830?
A stored cross-site scripting (XSS) vulnerability exists in the Forms feature of Liferay Portal and Liferay DXP. This issue allows remote attackers to inject arbitrary web scripts or HTML into a rich text field within forms. The vulnerability affects multiple versions of Liferay Portal and DXP, enabling the execution of malicious scripts when victims interact with affected forms.
Affected Version(s)
DXP 7.3.10 <= 7.3.10-u35
DXP 7.4.13 <= 7.4.13-u92
DXP 2023.Q3.1 <= 2023.Q3.8