CVE-2025-62261: Medium severity Liferay portal vulnerability
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62261?
CVE-2025-62261 is classified with a high severity due to the exposure of sensitive password reset tokens in plain text.
How do I fix CVE-2025-62261?
To fix CVE-2025-62261, upgrade to the latest version of Liferay Portal or Liferay DXP that addresses this vulnerability.
What versions are affected by CVE-2025-62261?
CVE-2025-62261 affects Liferay Portal versions 7.4.0 to 7.4.3.99 and Liferay DXP versions 2023.Q3.1 to 2023.Q3.4.
What is the risk of not addressing CVE-2025-62261?
Not addressing CVE-2025-62261 may allow attackers to gain unauthorized access to user accounts through compromised password reset tokens.
Is there a workaround for CVE-2025-62261?
Currently, there is no official workaround for CVE-2025-62261; upgrading to a patched version is the recommended mitigation.