CVE-2025-43745 – com.liferay.portal:release.portal.bom
Package
Manager: maven
Name: com.liferay.portal:release.portal.bom
Vulnerable Version: >=7.4.0-ga1 <=7.4.3.132-ga132
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.00064 pctl0.20111
Details
Liferay Portal CSRF Vulnerability via Endpoint Parameter A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behalf of the authenticated user via the endpoint parameter.
Metadata
Created: 2025-08-19T21:30:36Z
Modified: 2025-08-20T19:06:40Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-7q33-gwcm-r6cj/GHSA-7q33-gwcm-r6cj.json
CWE IDs: ["CWE-352"]
Alternative ID: GHSA-7q33-gwcm-r6cj
Finding: F007
Auto approve: 1