CVE-2025-62252: Medium severity Liferay portal vulnerability
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance via the comliferayusersadminwebportletUsersAdminPortletaddUserIds parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62252?
CVE-2025-62252 has a medium severity rating due to the risk it poses to authenticated users in accessing unauthorized data.
How do I fix CVE-2025-62252?
To mitigate CVE-2025-62252, upgrade Liferay Portal to version 7.4.3.112 or later, and Liferay DXP to version 2023.Q4.6 or later.
What versions of Liferay are affected by CVE-2025-62252?
CVE-2025-62252 affects Liferay Portal versions 7.4.0 to 7.4.3.111 and Liferay DXP versions 2023.Q4.0 to 2023.Q4.5.
Who is vulnerable to CVE-2025-62252?
Remote authenticated users with access to vulnerable versions of Liferay Portal and DXP are susceptible to CVE-2025-62252.
What types of attacks can CVE-2025-62252 facilitate?
CVE-2025-62252 can facilitate unauthorized access to sensitive data by exploiting insecure direct object references.