Логотип exploitDog
bind:CVE-2025-43798
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43798

Количество 2

Количество 2

nvd логотип

CVE-2025-43798

5 месяцев назад

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4p5r-3jmm-652q

5 месяцев назад

Liferay DXP Missing Critical Step in Authentication

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43798

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4p5r-3jmm-652q

Liferay DXP Missing Critical Step in Authentication

0%
Низкий
5 месяцев назад

Уязвимостей на страницу