Denial of Service in Liferay Portal by Excessive File Upload
CVE-2025-43736

6.9MEDIUM

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
12 August 2025

What is CVE-2025-43736?

A Denial of Service vulnerability exists in Liferay Portal versions 7.4.3.0 through 7.4.3.132 and several releases of Liferay DXP. The flaw allows users to upload profile pictures exceeding the maximum size limit of 300kb, which can degrade system performance as the portal struggles to manage excessive data. This condition can lead to slower response times and overall diminished usability for users accessing the portal.

Affected Version(s)

DXP 7.4.13 <= 7.4.13-u92

DXP 2024.Q1.1 <= 2024.Q1.16

DXP 2024Q2.0 <= 2023.Q2.13

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lorenzo Toti, Francesco Dalena, Simone Capparelli and the company DXC Technology
.