Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published: 2025-10-27T22:13:35.880Z
Updated: 2025-10-28T19:48:15.967Z
Reserved: 2025-10-09T20:58:53.011Z
Link: CVE-2025-62259
Updated: 2025-10-28T19:48:03.202Z
Status : Received
Published: 2025-10-27T23:15:38.670
Modified: 2025-10-27T23:15:38.670
Link: CVE-2025-62259
No data.
ReportizFlow