Home
MEDIUM: 4.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:NDefault status
unaffected
7.4.0 (maven)
affected
Default status
unaffected
7.4.13 (maven)
affected
2024.Q1.1 (maven)
affected
2024.Q2.0 (maven)
affected
2024.Q3.0 (maven)
affected
2024.Q4.0 (maven)
affected
2025.Q1.0 (maven)
affected
2025.Q2.0 (maven)
affected
Description
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
Problem types
Product status
7.4.0 (maven)
7.4.13 (maven)
2024.Q1.1 (maven)
2024.Q2.0 (maven)
2024.Q3.0 (maven)
2024.Q4.0 (maven)
2025.Q1.0 (maven)
2025.Q2.0 (maven)
References
liferay.dev/...-/asset_publisher/jekt/content/CVE-2025-43773