CVE-2025-43750 Liferay form upload field allows to obfuscate file extensions

Description

Liferay Portal and Liferay DXP allows remote unauthenticated users (guests) to upload files via the form attachment field without proper validation, enabling extension obfuscation and bypassing MIME type checks.

Severity

5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N)

Affected Version(s)

  • Liferay Portal 7.4.0 through 7.4.3.132
  • Liferay DXP 2025.Q1.0 through 2025.Q1.1
  • Liferay DXP 2024.Q4.0 through 2024.Q4.7
  • Liferay DXP 2024.Q3.1 through 2024.Q3.13
  • Liferay DXP 2024.Q2.0 through 2024.Q2.12
  • Liferay DXP 2024.Q1.1 through 2024.Q1.19
  • Liferay DXP 7.4

Fixed Version(s)

  • Liferay Portal fixed on master branch
  • Liferay DXP 2025.Q2.0
  • Liferay DXP 2025.Q1.2

Publication date: Mon, 17 Mar 2025 18:46:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.

Community
Company
Feedback