CVE-2025-43767 – com.liferay:com.liferay.info.impl
Package
Manager: maven
Name: com.liferay:com.liferay.info.impl
Vulnerable Version: >=0 <5.0.69
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS: 0.00054 pctl0.16693
Details
Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
Metadata
Created: 2025-08-23T06:30:19Z
Modified: 2025-08-25T20:46:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-6hj4-v2qp-cqr2/GHSA-6hj4-v2qp-cqr2.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-6hj4-v2qp-cqr2
Finding: F156
Auto approve: 1