{"id":71223,"date":"2025-10-08T18:46:23","date_gmt":"2025-10-08T15:16:23","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-43771-liferay-portal-and-dxp-xss-vulnerabilities\/"},"modified":"2025-10-08T18:46:23","modified_gmt":"2025-10-08T15:16:23","slug":"cve-2025-43771-liferay-portal-and-dxp-xss-vulnerabilities","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-43771-liferay-portal-and-dxp-xss-vulnerabilities\/","title":{"rendered":"CVE-2025-43771 &#8211; Liferay Portal and DXP XSS Vulnerabilities"},"content":{"rendered":"<p>CVE ID : CVE-2025-43771<\/p>\n<p>Published :  Oct. 8, 2025, 3:16 p.m. | 1\u00a0hour, 21\u00a0minutes ago<\/p>\n<p>Description : Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user\u2019s \u201cFirst Name\u201d text field, (2) a user\u2019s \u201cMiddle Name\u201d text field, (3) a user\u2019s \u201cLast Name\u201d text field, (4) the \u201cOther Reason\u201d text field when flagging content, or (5) the name of the flagged content.<\/p>\n<p>Severity: 4.8 | MEDIUM<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-43771 Published : Oct. 8, 2025, 3:16 p.m. | 1\u00a0hour, 21\u00a0minutes ago Description : Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-71223","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=71223"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71223\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=71223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=71223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=71223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}