CVE-2025-43758

Description

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.07

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.frontend.js.web 5.0.125Windows
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.object.web 1.0.219Windows
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.object.dynamic.data.mapping.form.field.type 1.0.65Windows
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.frontend.js.web for Linux 5.0.125Linux
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.object.web for Linux 1.0.219Linux
Vulnerabilities CVE-2025-43758 are fixed in Liferay - com.liferay.object.dynamic.data.mapping.form.field.type for Linux 1.0.65Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234