CVE-2025-43809 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Liferay Portal versions 7.4.0 through 7.4.3.111 and older unsupported versions, as well as Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, and 7.4 GA through update 92. This vulnerability allows an unauthenticated attacker to register a server license by manipulating the 'orderUuid' parameter. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low integrity impact (license registration) without affecting confidentiality or availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received no community discussion or media coverage, indicating a low level of public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.4CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | ||
>= 2023.q3.1, < 2023.q3.9CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | ||
>= 2023.Q4.0, < 2023.Q4.8CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.3.112CPE matchmatch criteria | cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.