← Back

CVE-2025-43759

nvd nist
Published: Aug 22, 2025Modified: Dec 16, 2025

JSON object

Loading...
6.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@liferay.com (Secondary)

Description

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows admin users of a virtual instance to add pages that are not in the default/main virtual instance, then any tenant can create a list of all other tenants.

Affected (7)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
From 2024.Q1.1 to 2024.Q1.15
From 2024.q2.0 to 2024.q2.13
From 2024.q3.1 to 2024.q3.13
From 2024.q4.0 to 2024.q4.7
Version 2025.q1.0
Version 7.4
From 7.4.0 to 7.4.3.132

Timeline

No history available yet.