Логотип exploitDog
bind:CVE-2025-43772
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43772

Количество 2

Количество 2

nvd логотип

CVE-2025-43772

5 месяцев назад

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

EPSS: Низкий
github логотип

GHSA-j4fw-4mhr-hc45

5 месяцев назад

Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43772

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

0%
Низкий
5 месяцев назад
github логотип
GHSA-j4fw-4mhr-hc45

Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin

0%
Низкий
5 месяцев назад

Уязвимостей на страницу