Access Control Issue in Liferay Portal and DXP Products
CVE-2025-43768
5.1MEDIUM
What is CVE-2025-43768?
A security vulnerability in Liferay Portal versions 7.4.0 through 7.4.3.131 and multiple versions of Liferay DXP allows authenticated users, regardless of their permissions, to access sensitive admin user information via the JSONWS APIs. This flaw not only compromises the confidentiality of sensitive data but could also lead to unauthorized administrative actions if exploited. It is essential for users of affected versions to implement necessary patches and updates to mitigate potential risks associated with this vulnerability.
Affected Version(s)
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.15
DXP 2024.Q2.0 <= 2024.Q2.13