CVE-2025-43763
Last modified
CVE-2025-43763 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into making unauthorized requests to other instances, creating new object entries that link to external resources.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into making unauthorized requests to other instances, creating new object entries that link to external resources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Digital Experience Platform | >= 2024.q1.1, < 2024.q1.21 |
| Liferay | Digital Experience Platform | >= 2024.q2.0, <= 2024.q2.13 |
| Liferay | Digital Experience Platform | >= 2024.Q3.0, <= 2024.Q3.13 |
| Liferay | Digital Experience Platform | >= 2024.q4.0, <= 2024.q4.7 |
| Liferay | Liferay Portal | >= 7.4.0, < 7.4.3.132 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-43763?
How severe is CVE-2025-43763?
How do I fix CVE-2025-43763?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43758Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…5.3
- CVE-2025-43759Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…2.7
- CVE-2025-4376Improper Input Validation vulnerability in Sparx Systems Pro…5.3
- CVE-2025-43760A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-43761A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2025-43762Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025…6.5
- CVE-2025-43764Self-ReDoS (Regular expression Denial of Service) exists wit…6.5
- CVE-2025-43765A Stored cross-site scripting vulnerability in the Liferay P…6.1
- CVE-2025-43766The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP …9.8
- CVE-2025-43767Open Redirect vulnerability in /c/portal/edit_info_item para…6.1
- CVE-2025-43768Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024…7.7
- CVE-2025-43769Stored cross-site scripting (XSS) vulnerability in Liferay P…6.1
Are you affected by CVE-2025-43763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
