CVE-2025-43813
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
29/09/2025
Last modified:
11/12/2025
Description
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrary CSS and JSS files and load the files multiple times via the query string in a URL.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 7.3 (excluding) | |
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2023.q3.1 (including) | 2023.q3.9 (excluding) |
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2023.Q4.0 (including) | 2023.Q4.5 (excluding) |
| cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_2:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



