CVE-2025-43788Missing Authorization in Digital Experience Platform

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 83.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12

Description

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.4.3.947.4.3.125+1
CVEListV5liferay/portal7.4.3.947.4.3.124
NVDliferay/digital_experience_platform2024.Q1.12024.Q1.13+1
CVEListV5liferay/dxp7.4.13-u817.4.13-u85+1

🔴Vulnerability Details

3
CVEList
CVE-2025-43788: The organization selector in Liferay Portal 72025-09-12
OSV
Liferay Portal's Organization Selector exposes organization data to remote authenticated users2025-09-12
GHSA
Liferay Portal's Organization Selector exposes organization data to remote authenticated users2025-09-12

📋Vendor Advisories

2
Microsoft
DOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)2024-08-13
Microsoft
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()2023-10-10
CVE-2025-43788 — Missing Authorization | cvebase