CVE-2025-43809

MEDIUM

Liferay Portal 7.4.0-7.4.3.111 and Liferay DXP < 2023.Q4.8 - Cross-Site Request Forgery via License Registration

Title source: llm
STIX 2.1

Description

Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers to register a server license via the 'orderUuid' parameter.

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (3)
com.liferay.portal/com.liferay.portal.impl 0 - 101.0.0Maven
liferay/digital_experience_platform < 7.4
liferay/liferay_portal 7.4.0 - 7.4.3.112
Published Sep 19, 2025
Tracked Since Feb 18, 2026