Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31659 | Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a web content structure's Name text field |
Github GHSA |
GHSA-jv8x-mm3v-75r7 | Liferay Portal vulnerable to cross-site scripting in the web content template |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Mon, 29 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a web content structure's Name text field | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-09-30T14:45:51.855Z
Reserved: 2025-04-17T10:55:35.683Z
Link: CVE-2025-43812
Updated: 2025-09-30T14:45:49.534Z
Status : Awaiting Analysis
Published: 2025-09-29T23:15:31.207
Modified: 2025-10-02T19:12:42.843
Link: CVE-2025-43812
No data.
OpenCVE Enrichment
Updated: 2025-09-30T08:47:49Z
EUVD
Github GHSA