
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43797 is an insecure default initialization vulnerability in Liferay Portal and Liferay DXP that allows any registered user to automatically join newly created sites due to an "Open" default membership type. It affects Liferay Portal versions 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions. The vulnerability was published on September 15, 2025, with the GitHub Advisory following on September 16, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Liferay Advisory).
The root cause is classified as CWE-1188 (Insecure Default Initialization of Resource): when a new site is created in Liferay Portal or DXP, the default membership type is set to "Open," meaning any registered user can join without administrator approval. An attacker with a valid low-privilege account can exploit this by simply joining any newly created site and then leveraging site membership permissions to view, add, or edit site content. The affected Maven package is com.liferay:com.liferay.site.admin.web, with versions below 5.0.111 being vulnerable. No complex attack prerequisites or special conditions are required beyond having a registered account on the platform (GitHub Advisory, Liferay Advisory).
A remote attacker with a low-privilege registered account can exploit this vulnerability to gain unauthorized site membership, potentially viewing restricted site content (confidentiality impact), and adding or editing content within the site (integrity impact). Availability is not impacted. The scope is limited to the vulnerable system, with no evidence of lateral movement to subsequent systems; however, unauthorized content manipulation could affect the integrity of business-critical information hosted on affected Liferay sites (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.164% (0.00164), indicating a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability has been detected by Qualys scanners (detection IDs 520075 and 733443).
Liferay has released a patch in the Maven package com.liferay:com.liferay.site.admin.web version 5.0.111 and later. For Liferay Portal, upgrade to version 7.4.3.112 or later; for DXP, upgrade beyond the affected versions (7.3 update 35, 7.4 update 92, 2023.Q3.4, or 2023.Q4.0). As an immediate workaround, administrators should review all existing sites and manually change the membership type from "Open" to "Restricted" or "Private" to prevent unauthorized self-enrollment. Additionally, implement stricter access controls for site creation and regularly audit site membership policies (GitHub Advisory, Liferay Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."