PT-2025-35502 · Liferay · Liferay 7.4+2

Published

2025-09-01

·

Updated

2025-12-12

·

CVE-2025-3586

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.27 through 7.4.3.42 Liferay DXP versions 2023.Q3.1 through 2023.Q3.10 Liferay DXP versions 2023.Q4.0 through 2023.Q4.10 Liferay DXP versions 2024.Q1.1 through 2024.Q1.20 Liferay 7.4 update 27 through update 42
Description The Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users, allowing remote authenticated admin users with the Instance Administrator role to execute arbitrary Groovy scripts through Object actions.
Recommendations Liferay Portal versions 7.4.3.27 through 7.4.3.42: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q3.1 through 2023.Q3.10: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q4.0 through 2023.Q4.10: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2024.Q1.1 through 2024.Q1.20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay 7.4 update 27 through update 42: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3586
GHSA-M5GV-VJ3F-6V2P

Affected Products

Liferay 7.4
Liferay Dxp
Liferay Portal