GHSA-5c6v-fqcw-w6q5

Suggest an improvement
Source
https://github.com/advisories/GHSA-5c6v-fqcw-w6q5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5c6v-fqcw-w6q5/GHSA-5c6v-fqcw-w6q5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5c6v-fqcw-w6q5
Aliases
  • CVE-2025-43791
Published
2025-09-15T18:31:06Z
Modified
2025-09-15T23:57:19.036383Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal vulnerable to Cross-site Scripting
Details

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text" type field to (1) a web content structure, (2) a Documents and Media Document Type , or (3) custom assets that uses the Data Engine's module Rich Text field.

Database specific
{
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed_at": "2025-09-15T23:32:11Z",
    "nvd_published_at": "2025-09-15T18:15:37Z"
}
References

Affected packages

Maven / com.liferay:com.liferay.dynamic.data.mapping.form.field.type

Package

Name
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.dynamic.data.mapping.form.field.type

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.167

Affected versions

1.*

1.0.0

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.27
3.0.28
3.0.29
3.0.30
3.0.31
3.0.32
3.0.33
3.0.34
3.0.35
3.0.36
3.0.37
3.0.38
3.0.39
3.0.40
3.0.41
3.0.42
3.0.43
3.0.44
3.0.45
3.0.46
3.0.47
3.0.48
3.0.49
3.0.50
3.0.51
3.0.52
3.0.53
3.0.54
3.0.55
3.0.56
3.0.57
3.0.58
3.0.59
3.0.60
3.0.61
3.0.62
3.0.63
3.0.64
3.0.65
3.0.66
3.0.67
3.0.68
3.0.69
3.0.70
3.0.71
3.0.72
3.0.73

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.0.10
4.0.11
4.0.12
4.0.13
4.0.14
4.0.15
4.0.16
4.0.17
4.0.18
4.0.19
4.0.20
4.0.21
4.0.22
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.47
4.0.48
4.0.49
4.0.50
4.0.51
4.0.52
4.0.53
4.0.54
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.60
4.0.61
4.0.62
4.0.63
4.0.64
4.0.65
4.0.66
4.0.67
4.0.68
4.0.69
4.0.70
4.0.71
4.0.72
4.0.73
4.0.74
4.0.75
4.0.76
4.0.77
4.0.78
4.0.79
4.0.80
4.0.81
4.0.82
4.0.83
4.0.84
4.0.85
4.0.86
4.0.87
4.0.88
4.0.89
4.0.90
4.0.91
4.0.92
4.0.93
4.0.94
4.0.95
4.0.96
4.0.97
4.0.98
4.0.99
4.0.100
4.0.101
4.0.102
4.0.103
4.0.104
4.0.105
4.0.106
4.0.107
4.0.108
4.0.109
4.0.110
4.0.111
4.0.112
4.0.113
4.0.114
4.0.115
4.0.116
4.0.117
4.0.118
4.0.119

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.30
5.0.31
5.0.32
5.0.33
5.0.34
5.0.35
5.0.36
5.0.37
5.0.38
5.0.39
5.0.40
5.0.41
5.0.42
5.0.43
5.0.44
5.0.45
5.0.46
5.0.47
5.0.48
5.0.49
5.0.50
5.0.51
5.0.52
5.0.53
5.0.54
5.0.55
5.0.56
5.0.57
5.0.58
5.0.59
5.0.60
5.0.61
5.0.62
5.0.63
5.0.64
5.0.65
5.0.66
5.0.67
5.0.68
5.0.69
5.0.70
5.0.71
5.0.72
5.0.73
5.0.74
5.0.75
5.0.76
5.0.77
5.0.78
5.0.79
5.0.80
5.0.81
5.0.82
5.0.83
5.0.84
5.0.85
5.0.86
5.0.87
5.0.88
5.0.89
5.0.90
5.0.91
5.0.92
5.0.93
5.0.94
5.0.95
5.0.96
5.0.97
5.0.98
5.0.99
5.0.100
5.0.101
5.0.102
5.0.103
5.0.104
5.0.105
5.0.106
5.0.107
5.0.108
5.0.109
5.0.110
5.0.111
5.0.112
5.0.113
5.0.114

6.*

6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
6.0.10
6.0.11
6.0.12
6.0.13
6.0.14
6.0.15
6.0.16
6.0.17
6.0.18
6.0.19
6.0.20
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
6.0.26
6.0.27
6.0.28
6.0.29
6.0.30
6.0.31
6.0.32
6.0.33
6.0.34
6.0.35
6.0.36
6.0.37
6.0.38
6.0.39
6.0.40
6.0.41
6.0.42
6.0.43
6.0.44
6.0.45
6.0.46
6.0.47
6.0.48
6.0.49
6.0.50
6.0.51
6.0.52
6.0.53
6.0.54
6.0.55
6.0.56
6.0.57
6.0.58
6.0.59
6.0.60
6.0.61
6.0.62
6.0.63
6.0.64
6.0.65
6.0.66
6.0.67
6.0.68
6.0.69
6.0.70
6.0.71
6.0.72
6.0.73
6.0.74
6.0.75
6.0.76
6.0.77
6.0.78
6.0.79
6.0.80
6.0.81
6.0.82
6.0.83
6.0.84
6.0.85
6.0.86
6.0.87
6.0.88
6.0.89
6.0.90
6.0.91
6.0.92
6.0.93
6.0.94
6.0.95
6.0.96
6.0.97
6.0.98
6.0.99
6.0.100
6.0.101
6.0.102
6.0.103
6.0.104
6.0.105
6.0.106
6.0.107
6.0.108
6.0.109
6.0.110
6.0.111
6.0.112
6.0.113
6.0.114
6.0.115
6.0.116
6.0.117
6.0.118
6.0.119
6.0.120
6.0.121
6.0.122
6.0.123
6.0.124
6.0.125
6.0.126
6.0.127
6.0.128
6.0.129
6.0.130
6.0.131
6.0.132
6.0.133
6.0.134
6.0.135
6.0.136
6.0.137
6.0.138
6.0.139
6.0.140
6.0.141
6.0.142
6.0.143
6.0.144
6.0.145
6.0.146
6.0.147
6.0.148
6.0.149
6.0.150
6.0.151
6.0.152
6.0.153
6.0.154
6.0.155
6.0.156
6.0.157
6.0.158
6.0.159
6.0.160
6.0.161
6.0.162
6.0.163
6.0.164
6.0.165
6.0.166