Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25497 | A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp |
|
| Vendors & Products |
Liferay
Liferay dxp |
Thu, 21 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-08-21T20:52:21.478Z
Reserved: 2025-04-17T10:55:23.317Z
Link: CVE-2025-43747
Updated: 2025-08-21T20:52:18.879Z
Status : Awaiting Analysis
Published: 2025-08-21T21:15:35.463
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-43747
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:35Z
EUVD