CVE-2025-43743 User enumeration in calendar portlet

Description

Liferay Portal and Liferay DXP allows any authenticated remote user to view other calendars by allowing them to enumerate the names of other users, given an attacker the possibility to send phishing to these users.

Severity

5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N)

Affected Version(s)

  • Liferay Portal 7.4.0 through 7.4.3.132
  • Liferay DXP 2025.Q1.0 through 2025.Q1.5
  • Liferay DXP 2024.Q4.0 through 2024.Q4.7
  • Liferay DXP 2024.Q3.1 through 2024.Q3.13
  • Liferay DXP 2024.Q2.0 throguh 2024.Q2.13
  • Liferay DXP 2024.Q1.1 through 2024.Q1.15
  • Liferay DXP 7.4 GA through update 92

Fixed Version(s)

  • Liferay Portal fixed on master branch.
  • Liferay DXP 2025.Q2.0
  • Liferay DXP 2025.Q1.6
  • Liferay DXP 2024.Q1.16

Publication date: Tue, 08 Apr 2025 18:48:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.

Community
Company
Feedback