CVE Database
/

CVE-2025-43747

Back to search

CVE-2025-43747

Published: Aug 21, 2025

Modified: Aug 21, 2025

PUBLISHED

Description

A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.

VendorProductVersions

Liferay

DXP

affected
2025.Q2.0 - <= 2025.Q2.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now