CVE-2025-43745Cross-Site Request Forgery in Digital Experience Platform

Severity
6.9MEDIUMNVD
EPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19

Description

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behalf of the authenticated user via the endpoint parameter.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5liferay/portal7.4.07.4.3.132
NVDliferay/liferay_portal7.4.07.4.3.132
NVDliferay/digital_experience_platform2024.q1.12024.q1.20+6
CVEListV5liferay/dxp7.4.137.4.13-u92+6

🔴Vulnerability Details

3
GHSA
Liferay Portal CSRF Vulnerability via Endpoint Parameter2025-08-19
CVEList
CVE-2025-43745: A CSRF vulnerability in Liferay Portal 72025-08-19
OSV
Liferay Portal CSRF Vulnerability via Endpoint Parameter2025-08-19
CVE-2025-43745 — Cross-Site Request Forgery | cvebase