CVE-2025-43782

Description

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote authenticated users to access a workflow definition by name via the API

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.054

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-43782 are fixed in Liferay - com.liferay.portal.workflow.kaleo.runtime.integration.impl 5.0.48Windows
Vulnerabilities CVE-2025-43782 are fixed in Liferay - com.liferay.portal.workflow.kaleo.runtime.integration.impl for Linux 5.0.48Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234