CVE-2025-43825

MEDIUM

Liferay Portal <7.4.3.132 & DXP - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (4)
com.liferay/com.liferay.portal.template.freemarker 7.0.3 - 7.0.60Maven
liferay/digital_experience_platform 7.4
liferay/digital_experience_platform 2023.Q3.1 - 2023.Q3.10
liferay/liferay_portal 7.4.0 - 7.4.3.132
Published Oct 03, 2025
Tracked Since Feb 18, 2026