Replayable TOTP Auth in Liferay DXP 7.4 GA <92, 7.3 GA <35
CVE-2025-43798 Published on September 15, 2025

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a users TOTP to authenticate as the user.

NVD

Weakness Type

Missing Critical Step in Authentication

The software implements an authentication technique, but it skips a step that weakens the technique. Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.


Products Associated with CVE-2025-43798

Want to know whenever a new CVE is published for Liferay Digital Experience Platform? stack.watch will email you.

 

Affected Versions

Liferay DXP:

Exploit Probability

EPSS
0.03%
Percentile
9.58%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.