CVE-2025-3526
published 2025-06-16CVE-2025-3526: SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.48%
38.2th percentile
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | 7.0 – 7.2 | — |
| liferay | dxp | 6.2.0 – portal-173 | — |
| liferay | dxp | 7.0.10 – de-102 | — |
| liferay | dxp | 7.1.10 – dxp-28 | — |
| liferay | dxp | 7.2.10 – dxp-20 | — |
| liferay | dxp | 7.3.10 – 7.3.10-u25 | — |
| liferay | dxp | 7.4.13 – 7.4.13-u9 | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | 7.0.0 – 7.4.3.21 | — |
| liferay | portal | 7.0.0 – 7.4.3.21 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
osv·2025-06-16
CVE-2025-3526 [HIGH] Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
GHSA
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
ghsa·2025-06-16
CVE-2025-3526 [HIGH] CWE-400 Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-16
Published