CVE-2025-43779 | Liferay Portal/DXP cross site scripting (EUVD-2025-30939 / WID-SEC-2025-2118)
A vulnerability categorized as problematic has been discovered in Liferay Portal and DXP. Affected is an unknown function. Such manipulation of the argument _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName leads to cross site scripting.
This vulnerability is documented as CVE-2025-43779. The attack can be executed remotely. There is not any exploit available.