CVE-2025-43737 | Liferay Portal/DXP cross site scripting
A vulnerability has been found in Liferay Portal and DXP and classified as problematic. Affected by this issue is some unknown functionality. Performing manipulation of the argument _com_liferay_journal_web_portlet_JournalPortlet_backURL results in cross site scripting.
This vulnerability was named CVE-2025-43737. The attack may be initiated remotely. There is no available exploit.