← Back

CVE-2025-43767

nvd nist
Published: Aug 23, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.1
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@liferay.com (Secondary)

Description

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.

Affected (11)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
From 2024.Q1.1 to 2024.Q1.13
From 2024.Q3.1 to 2024.Q3.10
From 2024.q2.0 to 2024.q2.13
Version 7.4 update86
Version 7.4 update87
Version 7.4 update88
Version 7.4 update89
Version 7.4 update90
Version 7.4 update91
Version 7.4 update92
From 7.4.3.86 to 7.4.3.132

Timeline

No history available yet.