CVE-2025-43824: XSS
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43824?
CVE-2025-43824 is classified as a high severity vulnerability due to the potential for remote exploitation.
How do I fix CVE-2025-43824?
To fix CVE-2025-43824, upgrade Liferay Portal to version 7.4.4 or later, and Liferay DXP to versions beyond 2023.Q4.5 or 2023.Q3.8.
What versions are affected by CVE-2025-43824?
CVE-2025-43824 affects Liferay Portal versions 7.4.0 through 7.4.3.111 and Liferay DXP 2023.Q4.0 to 2023.Q4.5 and 2023.Q3.1 to 2023.Q3.8.
What type of vulnerability is CVE-2025-43824?
CVE-2025-43824 is a web security vulnerability that involves improper handling of the Content-Disposition header.
Is there a workaround for CVE-2025-43824?
There is no known workaround for CVE-2025-43824; the recommended action is to upgrade vulnerable software.