CVE-2025-43752: Medium severity Liferay portal vulnerability
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored in the documentlibrary allowing an attacker to cause a potential DDoS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43752?
CVE-2025-43752 is classified as a critical vulnerability due to the unrestricted file upload capability.
How do I fix CVE-2025-43752?
To fix CVE-2025-43752, upgrade to Liferay Portal version 7.4.4 or higher and Liferay DXP version 2025.Q1.5 or higher.
What could happen if CVE-2025-43752 is exploited?
Exploitation of CVE-2025-43752 could allow an attacker to upload malicious files, leading to potential remote code execution.
Which versions of Liferay are affected by CVE-2025-43752?
Affected versions include Liferay Portal 7.4.0 through 7.4.3.132 and Liferay DXP across multiple 2024 and 2025 Q1 releases.
How can I determine if my Liferay installation is vulnerable to CVE-2025-43752?
Check your Liferay installation version against the affected versions listed for CVE-2025-43752 to determine vulnerability.