MEDIUM
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows remote attackers to determine if an account exist in the application via the create account page
Published Aug 22, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.31%
Description
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows remote attackers to determine if an account exist in the application via the create account page.
Affected products
-
- Version 2023.Q3.1StatusaffectedConstraints<=2023.Q3.10
- Version 2023.Q4.0StatusaffectedConstraints<=2023.Q4.10
- Version 2024.Q1.1StatusaffectedConstraints<=2024.Q1.14
- Version 2024.Q2.0StatusaffectedConstraints<=2024.Q2.13
- Version 2024.Q3.0StatusaffectedConstraints<=2024.Q3.13
- Version 2024.Q4.0StatusaffectedConstraints<=2024.Q4.7
- Version 7.4.13StatusaffectedConstraints<=7.4.13-u92
- Version
-
- Version 7.4.0StatusaffectedConstraints<=7.4.3.132
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Liferay | DXP | unaffected |
| ||||||||||||||||||||||||
| Liferay | Portal | unaffected |
|
OR
- ≥ 2023.Q3.1 · ≤ 2023.Q3.10
- ≥ 2023.q4.0 · ≤ 2023.q4.10
- ≥ 2024.Q1.11 · < 2024.Q1.15
- ≥ 2024.q2.0 · ≤ 2024.q2.13
- ≥ 2024.Q3.0 · ≤ 2024.Q3.13
- ≥ 2024.q4.0 · ≤ 2024.q4.7
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- ≥ 7.4.0 · ≤ 7.4.3.132
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25583 Advisory
- https://github.com/advisories/GHSA-xwc5-q44v-p6gg Advisory
- https://github.com/liferay/liferay-portal/commit/097597e31b596295cb993bac596a42f06ac1e6d8
- https://github.com/liferay/liferay-portal/commit/1205e7bbcc31c40180935044d39ebf158b5256e1
- https://github.com/liferay/liferay-portal/commit/4843e000995ef5fbe4e4f14dce23c2f3116940de
- https://github.com/liferay/liferay-portal/commit/4987ff8641b970db3dca14d75bb9687120107c3b
- https://github.com/liferay/liferay-portal/commit/4f3b52bc92875cd0a0958ea33dece09b8224e6dc
- https://github.com/liferay/liferay-portal/commit/609104647a5a0bb79627ef689a2f8dc9fe9fbb05
- https://github.com/liferay/liferay-portal/commit/7b8376791cfe22bfce14e5f241af1d158d535fd8
- https://github.com/liferay/liferay-portal/commit/7e9e29a9dac8e5b6db6f2a480c98b483584b2f87
- https://liferay.atlassian.net/browse/LPE-18203
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43751 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43751
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Liferay
Published Aug 22, 2025
Updated Aug 22, 2025
Reserved Apr 17, 2025
Link CVE-2025-43751
CISA Vulnrichment
Updated Aug 22, 2025
ENISA EUVD
EUVD-2025-25583 GHSA-XWC5-Q44V-P6GG Assigner Liferay
Published Aug 22, 2025
Updated Aug 22, 2025
Exploited since n/a
Link EUVD-2025-25583