CVE-2025-62244: Medium severity Liferay portal vulnerability
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92, and 7.3 GA through update 36 allows remote authenticated attackers to view the edit page of a publication via the comliferaychangetrackingwebportletPublicationsPortletctCollectionId parameter.
Other sources
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92, and 7.3 GA through update 36 allows remote authenticated attackers to view the edit page of a publication via the comliferaychangetrackingwebportletPublicationsPortletctCollectionId parameter.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62244?
CVE-2025-62244 is classified as a medium severity vulnerability due to its potential for unauthorized information access.
How do I fix CVE-2025-62244?
To fix CVE-2025-62244, upgrade Liferay Portal to version 7.4.3.112 or higher and Liferay DXP to version 2023.Q4.6 or later.
What software is affected by CVE-2025-62244?
CVE-2025-62244 affects Liferay Portal versions 7.3.1 through 7.4.3.111 and Liferay DXP versions within specific ranges, including 2023.Q3 and Q4.
What type of vulnerability is CVE-2025-62244?
CVE-2025-62244 is an insecure direct object reference (IDOR) vulnerability, allowing unauthorized viewing of edit permissions.
Can CVE-2025-62244 be exploited by unauthenticated users?
No, CVE-2025-62244 requires remote authenticated attackers to exploit the vulnerability.