In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a user’s password reminder answer via the audit events.
CVSS
No CVSS.
References
Configurations
No configuration.
History
22 Sep 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-22 23:15
Updated : 2025-09-24 18:11
NVD link : CVE-2025-43814
Mitre link : CVE-2025-43814
CVE.ORG link : CVE-2025-43814
JSON object : View
Products Affected
No product.
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data