CVE-2025-43767

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Aug 2025, 20:24

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de redirección abierta en el parámetro /c/portal/edit_info_item en Liferay Portal 7.4.3.86 a 7.4.3.131, y Liferay DXP 2024.Q3.1 a 2024.Q3.9, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.12 y 7.4 actualización 86 a 92 permite a un atacante explotar esta vulnerabilidad de seguridad para redirigir a los usuarios a un sitio malicioso.

23 Aug 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-23 04:15

Updated : 2025-08-25 20:24


NVD link : CVE-2025-43767

Mitre link : CVE-2025-43767

CVE.ORG link : CVE-2025-43767


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')