CVE-2025-43795
Severity CVSS v4.0:
MEDIUM
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
12/09/2025
Last modified:
16/12/2025
Description
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_SystemSettingsPortlet_redirect parameter.<br />
<br />
Open redirect vulnerability in the Instance Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_InstanceSettingsPortlet_redirect parameter.<br />
<br />
Open redirect vulnerability in the Site Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_site_admin_web_portlet_SiteSettingsPortlet_redirect parameter.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 7.3 (excluding) | |
| cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | 2023.Q3.0 (including) | 2023.Q3.5 (excluding) |
| cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_2:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update1:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:* | ||
| cpe:2.3:a:liferay:digital_experience_platform:7.3:update15:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



