CVE-2025-62253: Medium severity Liferay portal vulnerability
Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the comliferaylayoutadminwebportletGroupPagesPortletredirect parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62253?
CVE-2025-62253 is classified as a high severity vulnerability due to its potential for exploitation through open redirect mechanisms.
How do I fix CVE-2025-62253?
To mitigate CVE-2025-62253, upgrade to Liferay Portal version 7.4.4 or later, or Liferay DXP version 2023.Q4.1 or later.
Which versions are affected by CVE-2025-62253?
CVE-2025-62253 affects Liferay Portal versions 7.4.0 to 7.4.3.97 and Liferay DXP versions 2023.Q3.1 to 2023.Q3.4, among other older versions.
What type of vulnerability is CVE-2025-62253?
CVE-2025-62253 is an open redirect vulnerability that allows remote attackers to redirect users to arbitrary sites.
Can I still use Liferay Portal if it is affected by CVE-2025-62253?
While you can continue to use Liferay Portal affected by CVE-2025-62253, it is strongly recommended to apply the necessary updates to avoid potential exploitation.