CVE 4.8 MEDIUM

CVE-2025-43747_CVE-2025-43747

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Description

A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.

Basic Information

ID CVE-2025-43747
Source Liferay
Published Aug 21, 2025 at 20:23
Modified Aug 21, 2025 at 20:52

Affected Product

Vendor Liferay
Product DXP
Version 2025.Q2.0
Affected Versions Liferay DXP 2025.Q2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.