Email Content Manipulation in Liferay Portal and DXP by Liferay
CVE-2025-43739
5.3MEDIUM
What is CVE-2025-43739?
An exploit in Liferay Portal and Liferay DXP versions allows authenticated users to alter email content sent via the calendar portlet. This vulnerability can lead to phishing attacks within an organization, enabling attackers to impersonate legitimate users and deceive recipients with malicious emails.
Affected Version(s)
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.16
DXP 2024Q2.0 <= 2023.Q2.13