CVE-2025-43767
Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
EPSS 0.05%
Description
Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious site.
How to fix CVE-2025-43767
To remediate CVE-2025-43767, upgrade the affected package to a fixed version below.
- Maven/com.liferay:com.liferay.info.impl—upgrade to 5.0.69 or later
Is CVE-2025-43767 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.0.69
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |