CVE-2025-43767Open Redirect in Digital Experience Platform

CWE-601Open Redirect4 documents4 sources
Severity
5.1MEDIUMNVD
EPSS
0.0%
top 90.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23

Description

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.4.3.867.4.3.132
CVEListV5liferay/portal7.4.3.867.4.3.131
NVDliferay/digital_experience_platform2024.Q1.12024.Q1.13+3
CVEListV5liferay/dxp7.4.13-u867.4.13-u92+3

🔴Vulnerability Details

3
OSV
Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect2025-08-23
GHSA
Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect2025-08-23
CVEList
CVE-2025-43767: Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 72025-08-23
CVE-2025-43767 — Open Redirect | cvebase