Looking for the vulnerability index of Invicti's legacy products?
Liferay DXP Insertion of Sensitive Information Into Sent Data Vulnerability - CVE-2025-43825 - Vulnerability Database

Liferay DXP Insertion of Sensitive Information Into Sent Data Vulnerability - CVE-2025-43825

Medium
Reference: CVE-2025-43825
Title: Liferay DXP Insertion of Sensitive Information Into Sent Data Vulnerability
Overview:

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132 and Liferay DXP 2025.Q1.0 through 2025.Q1.4 2024.Q4.0 through 2024.Q4.5 2024.Q3.0 through 2024.Q3.13 2024.Q2.1 through 2024.Q2.13 2024.Q1.1 through 2024.Q1.12 2023.Q4.0 through 2023.Q4.10 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to and potentially render confidential information that should remain restricted.