CVE-2025-2565

MEDIUM

Liferay Portal/DXP - Info Disclosure

Title source: llm
STIX 2.1

Description

The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms.

Scores

CVSS v3 4.3
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (3)
com.liferay.portal/release.dxp.bom 2024.Q3.0 - 2024.Q3.1Maven
com.liferay.portal/release.portal.bom 7.4.0 - 7.4.3.129Maven
liferay/digital_experience_platform 7.4 (48 CPE variants)
Published Mar 20, 2025
Tracked Since Feb 18, 2026