CSRF Vulnerability in Liferay Portal and DXP Affecting Multiple Versions
CVE-2025-62258

7HIGH

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
27 October 2025

What is CVE-2025-62258?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Headless API of Liferay Portal and Liferay DXP, affecting several versions. This security flaw enables remote attackers to leverage the endpoint parameter to execute malicious API calls without authentication, potentially compromising the integrity and availability of the system. Users should update to the latest version to mitigate this risk.

Affected Version(s)

DXP 7.3.10 <= 7.3.10-u35

DXP 7.4.13 <= 7.4.13-u92

DXP 2023.Q3.1 <= 2023.Q3.4

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.