Denial of Service in Liferay Portal by Excessive File Upload
CVE-2025-43736
6.9MEDIUM
What is CVE-2025-43736?
A Denial of Service vulnerability exists in Liferay Portal versions 7.4.3.0 through 7.4.3.132 and several releases of Liferay DXP. The flaw allows users to upload profile pictures exceeding the maximum size limit of 300kb, which can degrade system performance as the portal struggles to manage excessive data. This condition can lead to slower response times and overall diminished usability for users accessing the portal.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.16
DXP 2024Q2.0 <= 2023.Q2.13
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lorenzo Toti, Francesco Dalena, Simone Capparelli and the company DXC Technology