CVE-2025-43749: Medium severity Liferay portal vulnerability
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded in the form and stored in documentlibrary
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43749?
CVE-2025-43749 has been classified as a high severity vulnerability due to its potential for unauthorized file uploads by unauthenticated users.
Which versions of Liferay are affected by CVE-2025-43749?
CVE-2025-43749 affects Liferay Portal versions 7.4.0 through 7.4.3.132 and multiple versions of Liferay DXP from 2024 to 2025.
How do I fix CVE-2025-43749?
To fix CVE-2025-43749, users should upgrade their Liferay Portal or DXP to the latest patched version provided by Liferay.
What exploitation method is associated with CVE-2025-43749?
CVE-2025-43749 allows unauthenticated users to exploit the vulnerability via URL for unauthorized file uploads.
Can CVE-2025-43749 lead to data breaches?
Yes, if exploited, CVE-2025-43749 can lead to data breaches by allowing unauthorized access to file uploads.