CVE-2025-62258: CSRF
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the endpoint parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62258?
CVE-2025-62258 is a critical cross-site request forgery (CSRF) vulnerability that allows remote attackers to execute any Headless API.
How do I fix CVE-2025-62258?
To mitigate CVE-2025-62258, upgrade to the latest patched version of Liferay Portal or Liferay DXP as specified in the security advisory.
Which versions are affected by CVE-2025-62258?
CVE-2025-62258 affects Liferay Portal versions 7.4.0 to 7.4.3.107, Liferay DXP versions 2023.Q3.1 to 2023.Q3.4, and several older unsupported versions.
What impact does CVE-2025-62258 have on my application?
CVE-2025-62258 allows attackers to perform unauthorized actions on behalf of users via the Headless API, potentially leading to data exposure or manipulation.
Is CVE-2025-62258 being actively exploited?
While specific exploitation details are not publicly documented, the nature of CSRF vulnerabilities raises a high risk of active exploitation in vulnerable systems.