CVE-2025-62241: Medium severity Liferay DXP vulnerability
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the comliferaycommerceorderwebinternalportletCommerceOrderPortletcommerceOrderId parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62241?
CVE-2025-62241 is classified as a high severity vulnerability due to its potential to expose sensitive shipment addresses.
How do I fix CVE-2025-62241?
To fix CVE-2025-62241, users should upgrade Liferay DXP to a version later than 2023.Q4.5 where the vulnerability is patched.
Who is affected by CVE-2025-62241?
CVE-2025-62241 affects remote authenticated users in Liferay DXP versions 2023.Q4.1 through 2023.Q4.5.
What type of vulnerability is CVE-2025-62241?
CVE-2025-62241 is an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized access to shipment addresses.
What can attackers do exploiting CVE-2025-62241?
Attackers exploiting CVE-2025-62241 can view shipment addresses of other virtual instances, leading to potential data exposure.