CVE-2025-43798Missing Critical Step in Authentication in Digital Experience Platform

Severity
2.1LOWNVD
CISA7.5
EPSS
0.0%
top 91.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateOct 9

Description

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDliferay/digital_experience_platform2023.q3.12023.q3.5+3
CVEListV5liferay/dxp7.3.107.3.10-u35+3

🔴Vulnerability Details

3
GHSA
Liferay DXP Missing Critical Step in Authentication2025-09-15
CVEList
CVE-2025-43798: Liferay DXP 20232025-09-15
OSV
Liferay DXP Missing Critical Step in Authentication2025-09-15

📋Vendor Advisories

1
CISA
Grafana Path Traversal Vulnerability2025-10-09
CVE-2025-43798 — LOW severity | cvebase