Логотип exploitDog
bind:CVE-2025-43825
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43825

Количество 2

Количество 2

nvd логотип

CVE-2025-43825

4 месяца назад

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rggc-gf6w-9q73

4 месяца назад

Liferay Portal exposes sensitive user data through its Freemarker template

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43825

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-rggc-gf6w-9q73

Liferay Portal exposes sensitive user data through its Freemarker template

0%
Низкий
4 месяца назад

Уязвимостей на страницу