关键漏洞信息 CVE-2025-43802 XSS with in Objects Description Stored cross-site scripting (XSS) vulnerability in a custom object's API endpoint in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter. Severity 4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/V:I/L:VA/N/SC:N/SI:N/SA:N) Affected Versions Liferay DXP 2023.Q3.1 through 2023.Q3.4 Liferay DXP 7.4 Update 51 through Update 92 Liferay DXP 7.3 Update 33 through Update 35 Liferay Portal 7.4.3.51 through 7.4.3.109 Fixed Versions Liferay Portal 7.4.3.110 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.1 Liferay DXP 2023.Q3.5 Liferay DXP 7.3 Update 36 Acknowledgments This issue was reported by Amin ACHOUR Publication Date Tue, 17 Sep 2024 11:57:00 +0000