Liferay Portal and Liferay DXP Unlimited File Upload Vulnerability Leading to Potential Denial-of-Service

Vulnerability

A vulnerability exists in Liferay Portal versions 7.4.0 to 7.4.3.132 and Liferay DXP in various 2024 and 2025 releases, allowing users to upload an unlimited number of files through forms. These files are stored in the document library, which could be exploited to create a potential denial-of-service condition.

Impact

Exploitation of this vulnerability could lead to a denial-of-service condition, causing potential disruption or degradation of service.

Remediation

Users can upgrade to Liferay Portal's master branch or Liferay DXP versions 2025.Q2.0, 2025.Q1.2, or 2024.Q1.15.

Added: Aug 22, 2025, 7:23 PM
Updated: Aug 22, 2025, 7:23 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.