← Back

CVE-2025-4604

nvd nist
Published: Aug 4, 2025Modified: Dec 15, 2025

JSON object

Loading...
6.9
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@liferay.com (Secondary)

Description

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell

Affected (20)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
From 2024.Q3.0 to 2024.Q3.13
From 2024.q1.1 to 2024.q1.19
From 2024.q2.0 to 2024.q2.13
From 2024.q4.0 to 2024.q4.7
From 2025.q1.0 to 2025.q1.15
Version 7.4
Version 7.4 update80
Version 7.4 update81
Version 7.4 update82
Version 7.4 update83
Version 7.4 update84
Version 7.4 update85
Version 7.4 update86
Version 7.4 update87
Version 7.4 update88
Version 7.4 update89
Version 7.4 update90
Version 7.4 update91
Version 7.4 update92
From 7.4.3.80 to 7.4.3.132

Timeline

No history available yet.