Remote Staging Vulnerability in Liferay Portal and Liferay DXP
CVE-2025-43792
2.3LOW
What is CVE-2025-43792?
Liferay Portal and Liferay DXP have a vulnerability that enables remote authenticated users to exfiltrate sensitive data by exploiting improper retrieval of the live site's remote address from the database. This flaw allows attackers to send data to a malicious server pretending to be a legitimate live site using specific parameters related to the export-import portlet. In order to successfully exploit this vulnerability, an attacker must also procure the staging server's shared secret and ensure that the attacker's server is whitelisted on the staging server.
Affected Version(s)
DXP 7.3.10 <= 7.3.10-u35
DXP 7.4.13 <= 7.4.13-u92
DXP 2023.Q3.1 <= 2023.Q3.4