Denial of Service in Liferay Portal by Excessive File Upload
CVE-2025-43736
6.9MEDIUM
What is CVE-2025-43736?
A Denial of Service vulnerability exists in Liferay Portal versions 7.4.3.0 through 7.4.3.132 and several releases of Liferay DXP. The flaw allows users to upload profile pictures exceeding the maximum size limit of 300kb, which can degrade system performance as the portal struggles to manage excessive data. This condition can lead to slower response times and overall diminished usability for users accessing the portal.
Affected Version(s)
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.16
DXP 2024Q2.0 <= 2023.Q2.13
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lorenzo Toti, Francesco Dalena, Simone Capparelli and the company DXC Technology