Listen to this Post
The CVE-2025-21665 vulnerability in Liferay Portal is a password enumeration flaw stemming from an insufficient account lockout mechanism. In affected versions, the system fails to properly enforce lockout policies during authentication attempts on specific endpoints. This allows remote attackers to perform sustained brute-force attacks without triggering an account lock, even when the account lockout feature is administratively enabled. The vulnerability permits an attacker to systematically test passwords against a known username. By analyzing the timing or error messages in the server’s responses, the attacker can determine whether a guessed password is incorrect without the account being locked out after the configured number of failed attempts. This bypass of the security control significantly reduces the time and effort required to discover a valid user password, leading to credential compromise.
Platform: Liferay Portal/DXP
Version: 7.4.0-7.4.3.119
Vulnerability: Password Enumeration
Severity: Moderate
date: 2024-10-30
Prediction: Patch available
What Undercode Say:
`curl -X POST http://[bash]/api/login -d ‘user=test&password=guess’`
`hydra -l username -P wordlist.txt http-post-form://target:port”/api/login:user=^USER^&password=^PASS^:F=invalid”`
`for pass in $(cat list.txt); do; curl -s http://target/login -d “user=admin&password=$pass” | grep -q “error” && echo “Failed: $pass” || echo “Success!”; done`
How Exploit:
Brute-force login requests.
Bypass account lockout.
Determine valid passwords.
Protection from this CVE
Apply patch 7.4.3.120.
Implement rate-limiting.
Use strong passwords.
Impact:
Credential compromise.
Unauthorized access.
Account takeover.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

