CVE-2025-43737

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Aug 2025, 14:40

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross site scripting (XSS) reflejado en Liferay Portal 7.4.3.132 y Liferay DXP 2025.Q2.0 a 2025.Q2.8 y 2025.Q1.0 a 2025.Q1.15 permite que un usuario autenticado remoto inyecte código JavaScript a través del parámetro _com_liferay_journal_web_portlet_JournalPortlet_backURL.

19 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 19:15

Updated : 2025-08-20 14:40


NVD link : CVE-2025-43737

Mitre link : CVE-2025-43737

CVE.ORG link : CVE-2025-43737


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')