
We found results for “”
CVE-2025-43793
Good to know:


Date: September 15, 2025
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that share the same TLD to read cookies set by the application.
Severity Score
Severity Score
Weakness Type (CWE)
Improper Validation of Specified Quantity in Input
CWE-1284Top Fix

Upgrade Version
Upgrade to version com.liferay.portal:com.liferay.portal.impl:96.0.0;com.liferay.portal:com.liferay.portal.kernel:130.0.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |