CVE-2025-43747
Last modified
CVE-2025-43747 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Digital Experience Platform | >= 2025.Q2.0, < 2025.Q2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-43747?
How severe is CVE-2025-43747?
How do I fix CVE-2025-43747?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43741A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43742A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2025-43743Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…4.3
- CVE-2025-43744A stored DOM-based Cross-Site Scripting (XSS) vulnerability …5.4
- CVE-2025-43745A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.1…6.5
- CVE-2025-43746A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43748Insufficient CSRF protection for omni-administrator users in…6.8
- CVE-2025-43749Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…5.3
- CVE-2025-4375Cross-Site Request Forgery (CSRF) vulnerability in Sparx Sys…6.9
- CVE-2025-43750Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…6.5
- CVE-2025-43751User enumeration vulnerability in Liferay Portal 7.4.0 throu…5.3
- CVE-2025-43752Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…6.5
Are you affected by CVE-2025-43747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
