CVE 7.1 HIGH

CVE-2025-43772_CVE-2025-43772

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

Basic Information

ID CVE-2025-43772
Source Liferay
Published Sep 4, 2025 at 01:57

Affected Product

Vendor Liferay
Product Portal
Version 7.0.0
Affected Versions Liferay Portal 7.0.0
Liferay DXP 6.2.0
Liferay DXP 7.0.10
Liferay DXP 7.1.10
Liferay DXP 7.2.10
Liferay DXP 7.3.10
Liferay DXP 7.4.13

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.