PT-2025-34479 · Liferay · Liferay Portal+1

Published

2025-08-22

·

Updated

2025-08-23

·

CVE-2025-43762

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.0 through 7.4.3.132 Liferay DXP versions 2025.Q1.0 through 2025.Q1.1 Liferay DXP versions 2024.Q4.0 through 2024.Q4.7 Liferay DXP versions 2024.Q3.1 through 2024.Q3.13 Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 Liferay DXP versions 2024.Q1.1 through 2024.Q1.14 Liferay DXP versions 7.4 GA through update 92
Description: The application allows users to upload an unlimited number of files through forms. These files are stored in the document library, potentially enabling an attacker to cause a denial-of-service (DDoS) condition.
Recommendations: Liferay Portal versions 7.4.0 through 7.4.3.132 should be updated. Liferay DXP versions 2025.Q1.0 through 2025.Q1.1 should be updated. Liferay DXP versions 2024.Q4.0 through 2024.Q4.7 should be updated. Liferay DXP versions 2024.Q3.1 through 2024.Q3.13 should be updated. Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 should be updated. Liferay DXP versions 2024.Q1.1 through 2024.Q1.14 should be updated. Liferay DXP versions 7.4 GA through update 92 should be updated.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-43762
GHSA-84PP-QR92-95C9

Affected Products

Liferay Dxp
Liferay Portal