
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43766 is an unrestricted file upload vulnerability (CWE-434) in the style books component of Liferay Portal and Liferay DXP that enables arbitrary code execution by attackers. It affects Liferay Portal versions 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92. The vulnerability was published on August 23, 2025, with a patch available for the affected Maven package com.liferay:com.liferay.style.book.web prior to version 2.0.117. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Liferay Advisory).
The root cause is CWE-434 (Unrestricted Upload of File with Dangerous Type): the style books component in Liferay Portal and DXP fails to properly validate or restrict the types of files that can be uploaded, and those uploaded files are subsequently processed within the server environment. This allows an attacker to upload a malicious file (e.g., a server-side script or executable) that is then executed by the application server, resulting in arbitrary code execution. The vulnerable Maven artifact is com.liferay:com.liferay.style.book.web in versions prior to 2.0.117, and the fix is tracked under Liferay issue LPE-18145 (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code on the affected Liferay Portal or DXP server, resulting in full compromise of confidentiality, integrity, and availability of the system. An attacker could gain unauthorized access to sensitive data stored within the platform, modify or destroy content, establish persistent backdoors, and potentially pivot to other systems within the network. The CVSS v3.1 score of 9.8 reflects the high impact across all three security dimensions with no authentication required (GitHub Advisory, Liferay Advisory).
/style-books/ or /o/style-book-web/) with non-standard file types (e.g., .jsp, .jspx, .war, .sh); unexpected outbound connections from the Liferay server to external IPs..jsp, .jspx, .py, .sh) in Liferay's document library, style books directory, or web application deployment directories; newly created files in [LIFERAY_HOME]/webapps/ or temp directories.catalina.out) showing execution of unexpected scripts or Java errors related to file processing.bash, sh, curl, wget, python); unusual network connections initiated by the Java process.Liferay has released a patch in the Maven package com.liferay:com.liferay.style.book.web version 2.0.117 and later. For Liferay Portal, upgrade to version 7.4.3.132 or later; for Liferay DXP, apply the relevant quarterly update beyond the affected ranges (2024.Q1.14+, 2024.Q2.14+, 2024.Q3.14+, or a later quarterly release). As interim workarounds, restrict access to the Style Books administration interface to trusted administrators only, implement a Web Application Firewall (WAF) to block uploads of dangerous file types, and monitor file upload activity for anomalies (GitHub Advisory, Liferay Advisory).
The vulnerability was noted by automated CVE tracking accounts on X (formerly Twitter) shortly after publication on August 23, 2025 (X/CVEnew). Red Hat published a security advisory entry for the CVE on August 25, 2025 (Red Hat). No significant independent researcher commentary or broader media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."