PT-2025-38085 · Liferay · Liferay Portal+1

Published

2025-09-16

·

Updated

2025-12-16

·

CVE-2025-43805

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.3.0 through 7.4.3.111 Liferay DXP versions 2023.Q3.1 through 2023.Q3.4 and 2023.Q4.0 Liferay Portal 7.4 GA through update 92 Liferay Portal 7.3 GA through update 35
Description The software does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.
Recommendations Liferay Portal versions prior to 7.4.3.112 Liferay DXP versions prior to 2023.Q4.1 Liferay Portal 7.4 GA update 93 and later Liferay Portal 7.3 GA update 36 and later

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-43805
GHSA-5PP7-M8X8-RC82

Affected Products

Liferay Dxp
Liferay Portal