Логотип exploitDog
bind:CVE-2025-62252
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62252

Количество 2

Количество 2

nvd логотип

CVE-2025-62252

4 месяца назад

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance via the _com_liferay_users_admin_web_portlet_UsersAdminPortlet_addUserIds parameter.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pfwq-mr9g-gq6m

4 месяца назад

Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62252

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance via the _com_liferay_users_admin_web_portlet_UsersAdminPortlet_addUserIds parameter.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-pfwq-mr9g-gq6m

Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key

0%
Низкий
4 месяца назад

Уязвимостей на страницу