Junglewise Threat Intelligence

CVE-2025-43761: Liferay Portal Reflected XSS in CKEditor component

CVE-2025-43761 · Severity: medium · CVSS 4 · Published 2025-08-22

Technologies: Liferay Portal. Vendors: Liferay, Maven, npm.

Executive brief

Liferay Portal and DXP are enterprise platforms used for building digital experiences and corporate portals. A security flaw in the integrated CKEditor component allows attackers to execute malicious scripts in a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Liferay Portal and Liferay DXP due to improper input neutralization in the CKEditor component. Specifically, the endpoint at 'frontend-editor-ckeditor-web/ckeditor/samples/old/ajax.html' fails to adequately sanitize user-supplied input. An unauthenticated remote attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking or unauthorized manipulation of the web interface. The issue has been addressed by updating the 'liferay-ckeditor' dependency to version 4.21.0-liferay.10.

Affected products

  • Liferay Liferay Portal 7.4.0 through 7.4.3.131, 7.4 GA through update 92
  • Liferay Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12

Timeline

  • 2025-08-22: disclosed
  • 2025-08-22: advisory

References

Related threats