Skip to main content

Authorization Bypass Through User-Controlled Key

CVE-2025-43732

Severity Medium
Score 4.8/10

Summary

Liferay Selector Web through 4.0.35, Liferay Portal 7.4.0 through 7.4.3.132 and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the "_com_liferay_roles_selector_web_portlet_RolesSelectorPortlet_groupId". When an organization administrator modifies this parameter "id" value, they can gain unauthorized access to user lists from other organizations.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-639 - Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Advisory Timeline

  • Published