Description
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 exists in the Asset Publisher configuration UI within the Source.js module. This vulnerability allows attackers to inject arbitrary JavaScript via DDM structure field labels which are then inserted into the DOM using innerHTML without proper encoding.
INFO
Published Date :
2025-08-19T19:34:31.861Z
Last Modified :
2025-08-20T14:14:39.334Z
Source :
Liferay
AFFECTED PRODUCTS
The following products are affected by CVE-2025-43744 vulnerability.
Vendors | Products |
---|---|
Liferay |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-43744.