Логотип exploitDog
bind:CVE-2025-62241
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62241

Количество 2

Количество 2

nvd логотип

CVE-2025-62241

4 месяца назад

Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fhcw-px4q-pmvv

4 месяца назад

Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62241

Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-fhcw-px4q-pmvv

Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key

CVSS3: 4.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу