CVE-2025-43824

Severity
4.8MEDIUM
EPSS
0.0%
top 90.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateOct 7

Description

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDliferay/liferay_portal< 7.4.3.112
Mavencom.liferay.portal:release.portal.bom7.4.0-ga17.4.3.112-ga112
CVEListV5liferay/portal7.4.07.4.3.111
NVDliferay/digital_experience_platform2023.q3.12023.q3.9+2
CVEListV5liferay/dxp7.4.137.4.13-u92+2

🔴Vulnerability Details

3
GHSA
Liferay Profile Widget does not prevent vCard extension spoofing2025-10-07
OSV
Liferay Profile Widget does not prevent vCard extension spoofing2025-10-07
CVEList
CVE-2025-43824: The Profile widget in Liferay Portal 72025-10-06
CVE-2025-43824 (MEDIUM CVSS 4.8) | The Profile widget in Liferay Porta | cvebase.io