PT-2025-34504 · Liferay · Liferay Portal+1

Published

2025-08-23

·

Updated

2025-08-23

·

CVE-2025-43767

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.3.86 through 7.4.3.131 Liferay DXP versions 2024.Q1.1 through 2024.Q1.12 Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 Liferay DXP versions 2024.Q3.1 through 2024.Q3.9 Liferay Portal versions 7.4 update 86 through update 92
Description: An Open Redirect vulnerability exists in the /c/portal/edit info item parameter redirect. This allows an attacker to redirect users to a malicious site.
Recommendations: Liferay Portal versions 7.4.3.86 through 7.4.3.131: Update to a newer version. Liferay DXP versions 2024.Q1.1 through 2024.Q1.12: Update to a newer version. Liferay DXP versions 2024.Q2.0 through 2024.Q2.13: Update to a newer version. Liferay DXP versions 2024.Q3.1 through 2024.Q3.9: Update to a newer version. Liferay Portal versions 7.4 update 86 through update 92: Update to a newer version.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-43767
GHSA-6HJ4-V2QP-CQR2

Affected Products

Liferay Dxp
Liferay Portal