CVE-2025-43767
Severity CVSS v4.0:
MEDIUM
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
23/08/2025
Last modified:
12/12/2025
Description
Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2024.Q1.1 (including) | 2024.Q1.13 (excluding) |
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2024.q2.0 (including) | 2024.q2.13 (including) |
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2024.Q3.1 (including) | 2024.Q3.10 (excluding) |
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* | 7.4.3.86 (including) | 7.4.3.132 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



