cbcvebase.
CVE-2025-43808
published 2025-09-19

CVE-2025-43808: The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through…

medium6.9CVSS 4.0
AVNACLATNPRNUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual products for free via a crafted URL.

Affected

10 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydigital_experience_platform
liferaydigital_experience_platform2023.Q3.1 – 2023.Q3.10
liferaydigital_experience_platform>= 2023.Q4.0 < 2023.Q4.92023.Q4.9
liferaydxp2023.Q3.1 – 2023.Q3.10
liferaydxp2023.Q4.0 – 2023.Q4.8
liferaydxp7.3.10 – 7.3.10-u36
liferaydxp7.4.13 – 7.4.13-u92
liferayliferay_portal>= 7.4.0 < 7.4.3.1137.4.3.113
liferayportal7.3.0 – 7.4.3.112