CVE-2025-43766Unrestricted File Upload in Digital Experience Platform

Severity
6.8MEDIUMNVD
EPSS
0.2%
top 61.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23

Description

The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.4.07.4.3.132
CVEListV5liferay/portal7.4.3.07.4.3.131
NVDliferay/digital_experience_platform2024.Q1.12024.Q1.14+4
CVEListV5liferay/dxp7.4.137.4.13-u92+4

🔴Vulnerability Details

3
OSV
Liferay Portal allows unrestricted upload of file in the style books component2025-08-23
GHSA
Liferay Portal allows unrestricted upload of file in the style books component2025-08-23
CVEList
CVE-2025-43766: The Liferay Portal 72025-08-23
CVE-2025-43766 — Unrestricted File Upload | cvebase