CVE-2025-43762

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allowing an attacker to cause a potential DDoS.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Aug 2025, 20:24

Type Values Removed Values Added
Summary
  • (es) Liferay Portal 7.4.0 a 7.4.3.132, y Liferay DXP 2025.Q1.0 a 2025.Q1.1, 2024.Q4.0 a 2024.Q4.7, 2024.Q3.1 a 2024.Q3.13, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.14 y 7.4 GA hasta la actualización 92 permiten a los usuarios cargar una cantidad ilimitada de archivos a través de los formularios, los archivos se almacenan en document_library lo que permite a un atacante provocar un posible DDoS.

22 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 19:15

Updated : 2025-08-25 20:24


NVD link : CVE-2025-43762

Mitre link : CVE-2025-43762

CVE.ORG link : CVE-2025-43762


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling