CVE-2025-43732
Last modified
CVE-2025-43732 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the _com_liferay_roles_selector_web_portlet_RolesSelectorPortlet_groupId. When an organization administrator modifies this parameter id value, they can gain unauthorized access to user lists from other organizations.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the _com_liferay_roles_selector_web_portlet_RolesSelectorPortlet_groupId. When an organization administrator modifies this parameter id value, they can gain unauthorized access to user lists from other organizations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Digital Experience Platform | >= 2024.Q1.1, < 2024.Q1.18 |
| Liferay | Digital Experience Platform | >= 2024.Q2.1, <= 2024.Q2.13 |
| Liferay | Digital Experience Platform | >= 2024.q3.1, <= 2024.q3.13 |
| Liferay | Digital Experience Platform | >= 2024.q4.0, <= 2024.q4.7 |
| Liferay | Digital Experience Platform | >= 2025.Q1.0, < 2025.Q1.11 |
| Liferay | Digital Experience Platform | 7.4 |
| Liferay | Liferay Portal | >= 7.4.0, <= 7.4.3.132 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-43732?
How severe is CVE-2025-43732?
How do I fix CVE-2025-43732?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43727Dell PowerProtect Data Domain with Data Domain Operating Sys…7.5
- CVE-2025-43728Dell ThinOS 10, versions prior to 2508_10.0127, contain a Pr…9.8
- CVE-2025-43729Dell ThinOS 10, versions prior to 2508_10.0127, contains an …7.8
- CVE-2025-4373A flaw was found in GLib, which is vulnerable to an integer …4.8
- CVE-2025-43730Dell ThinOS 10, versions prior to 2508_10.0127, contains an …7.8
- CVE-2025-43731A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43733A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43734A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43735A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2025-43736A Denial Of Service via File Upload (DOS) vulnerability in t…4.3
- CVE-2025-43737A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43738A reflected cross-site scripting (XSS) vulnerability in the …5.4
Are you affected by CVE-2025-43732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
