CVE-2025-43825: Medium severity Liferay portal vulnerability
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43825?
CVE-2025-43825 has been rated as high severity due to the potential for unauthorized access and data exposure.
How do I fix CVE-2025-43825?
To remediate CVE-2025-43825, upgrade to Liferay Portal version 7.4.3.133 or later, or Liferay DXP version 2025.Q1.5 or later.
Which versions are affected by CVE-2025-43825?
CVE-2025-43825 affects Liferay Portal versions 7.4.0 to 7.4.3.132 and multiple versions of Liferay DXP from 2023.Q3.1 to 2025.Q1.4.
What products are impacted by CVE-2025-43825?
CVE-2025-43825 impacts Liferay Portal and Liferay DXP products.
What are the potential risks associated with CVE-2025-43825?
The potential risks include data leakage, unauthorized access to sensitive information, and compromise of the affected systems.