CVE-2025-62261

Severity
6.9MEDIUM
EPSS
0.0%
top 93.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateOct 28

Description

Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages6 packages

NVDliferay/liferay_portal7.0.07.4.3.100
Mavencom.liferay.portal:release.portal.bom7.4.0-ga17.4.3.100
CVEListV5liferay/portal7.4.07.4.3.99
CVEListV5liferay/dxp7.3.107.3.10-u34+2

🔴Vulnerability Details

3
OSV
Liferay Portal Stores Password Reset Tokens in Plain Text2025-10-28
GHSA
Liferay Portal Stores Password Reset Tokens in Plain Text2025-10-28
CVEList
CVE-2025-62261: Liferay Portal 72025-10-27
CVE-2025-62261 (MEDIUM CVSS 6.9) | Liferay Portal 7.4.0 through 7.4.3. | cvebase.io