Логотип exploitDog
bind:CVE-2025-43824
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43824

Количество 2

Количество 2

nvd логотип

CVE-2025-43824

4 месяца назад

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pfxj-gvqg-mj44

4 месяца назад

Liferay Profile Widget does not prevent vCard extension spoofing

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43824

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-pfxj-gvqg-mj44

Liferay Profile Widget does not prevent vCard extension spoofing

0%
Низкий
4 месяца назад

Уязвимостей на страницу