A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains. | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Liferay
Published: 2025-08-21T20:23:20.040Z
Updated: 2025-08-21T20:52:21.478Z
Reserved: 2025-04-17T10:55:23.317Z
Link: CVE-2025-43747

Updated: 2025-08-21T20:52:18.879Z

Status : Received
Published: 2025-08-21T21:15:35.463
Modified: 2025-08-21T21:15:35.463
Link: CVE-2025-43747

No data.