CVE-2025-43771
MEDIUMLiferay Digital Experience Platform < 2023.Q3.4 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user’s “First Name” text field, (2) a user’s “Middle Name” text field, (3) a user’s “Last Name” text field, (4) the “Other Reason” text field when flagging content, or (5) the name of the flagged content.
Scores
CVSS v3
5.4
EPSS
0.0003
EPSS Percentile
6.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (3)
liferay/digital_experience_platform
< 2023.Q3.4
liferay/liferay_portal
< 7.4.3.112
com.liferay/com.liferay.flags.web
< 6.0.24Maven
Timeline
Published
Oct 08, 2025
Tracked Since
Feb 18, 2026