Количество 2
Количество 2
CVE-2025-62258
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
GHSA-gh4w-8qgq-8w9r
Liferay Portal Vulnerable to CSRF in Headless APIs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-62258 CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-gh4w-8qgq-8w9r Liferay Portal Vulnerable to CSRF in Headless APIs | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу