Home

Description

Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrary CSS and JSS files and load the files multiple times via the query string in a URL.

PUBLISHED Reserved 2025-04-17 | Published 2025-09-29 | Updated 2025-09-30 | Assigner Liferay




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-22: Path Traversal

Product status

Default status
unaffected

7.4.0
affected

Default status
unaffected

7.3.10
affected

7.4.13
affected

2023.Q3.1
affected

2023.Q4.0
affected

Credits

Sébastien Sauty reporter

References

liferay.dev/...-/asset_publisher/jekt/content/CVE-2025-43813

cve.org (CVE-2025-43813)

nvd.nist.gov (CVE-2025-43813)

Download JSON