Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25166 | Liferay Portal Email Modification Vulnerability via Calendar Portlet |
Github GHSA |
GHSA-7mxq-h2r7-h449 | Liferay Portal Email Modification Vulnerability via Calendar Portlet |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Tue, 19 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allow any authenticated user to modify the content of emails sent through the calendar portlet, allowing an attacker to send phishing emails to any other user in the same organization. | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-08-19T14:07:58.045Z
Reserved: 2025-04-17T10:55:20.338Z
Link: CVE-2025-43739
Updated: 2025-08-19T14:07:52.428Z
Status : Awaiting Analysis
Published: 2025-08-19T14:15:38.363
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-43739
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:31:59Z
EUVD
Github GHSA