CVE-2025-43767

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
LiferayCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
liferaydigital_experience_platform
2024.Q1.1 ≤
𝑥
< 2024.Q1.13
liferaydigital_experience_platform
2024.q2.0 ≤
𝑥
≤ 2024.q2.13
liferaydigital_experience_platform
2024.Q3.1 ≤
𝑥
< 2024.Q3.10
liferaydigital_experience_platform
7.4:update86
liferaydigital_experience_platform
7.4:update87
liferaydigital_experience_platform
7.4:update88
liferaydigital_experience_platform
7.4:update89
liferaydigital_experience_platform
7.4:update90
liferaydigital_experience_platform
7.4:update91
liferaydigital_experience_platform
7.4:update92
liferayliferay_portal
7.4.3.86 ≤
𝑥
< 7.4.3.132
𝑥
= Vulnerable software versions