Executive brief
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
Affected products
- Maven com.liferay.portal:com.liferay.portal.kernel
Junglewise Threat Intelligence
CVE-2025-43770 · Severity: medium · CVSS 4 · Published 2025-08-23
Technologies: com.liferay.portal:com.liferay.portal.kernel (Maven). Vendors: Maven.
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter