Логотип exploitDog
bind:CVE-2025-43758
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43758

Количество 2

Количество 2

nvd логотип

CVE-2025-43758

6 месяцев назад

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mm62-gwj5-j285

6 месяцев назад

Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43758

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-mm62-gwj5-j285

Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry

0%
Низкий
6 месяцев назад

Уязвимостей на страницу