7.1
CVE-2025-43748
- EPSS 0.02%
- Veröffentlicht 20.08.2025 14:28:21
- Zuletzt bearbeitet 16.12.2025 14:59:16
- Quelle security@liferay.com
- CVE-Watchlists
- Unerledigt
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attackers to execute Cross-Site Request Forgery
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version >= 7.0 <= 7.4
Liferay ≫ Digital Experience Platform Version >= 2023.Q3.1 <= 2023.Q3.9
Liferay ≫ Digital Experience Platform Version >= 2023.Q4.0 <= 2023.Q4.9
Liferay ≫ Digital Experience Platform Version >= 2024.Q1.1 < 2024.Q1.7
Liferay ≫ Liferay Portal Version >= 7.0.0 < 7.4.3.120
Liferay ≫ Liferay Portal Version6.2 Update- SwEditionenterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.046 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
| security@liferay.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.