CVE 5.3 MEDIUM

CVE-2025-43788_CVE-2025-43788

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Basic Information

ID CVE-2025-43788
Source Liferay
Published Sep 12, 2025 at 02:22

Affected Product

Vendor Liferay
Product Portal
Version 7.4.3.94
Affected Versions Liferay Portal 7.4.3.94
Liferay DXP 7.4.13-u81
Liferay DXP 2024.Q1.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.