Remote Staging Vulnerability in Liferay Portal and Liferay DXP
CVE-2025-43792

2.3LOW

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
15 September 2025

What is CVE-2025-43792?

Liferay Portal and Liferay DXP have a vulnerability that enables remote authenticated users to exfiltrate sensitive data by exploiting improper retrieval of the live site's remote address from the database. This flaw allows attackers to send data to a malicious server pretending to be a legitimate live site using specific parameters related to the export-import portlet. In order to successfully exploit this vulnerability, an attacker must also procure the staging server's shared secret and ensure that the attacker's server is whitelisted on the staging server.

Affected Version(s)

DXP 7.3.10 <= 7.3.10-u35

DXP 7.4.13 <= 7.4.13-u92

DXP 2023.Q3.1 <= 2023.Q3.4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43792 : Remote Staging Vulnerability in Liferay Portal and Liferay DXP