CVE-2025-62262

Severity
4.6MEDIUM
EPSS
0.0%
top 97.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27

Description

Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDliferay/liferay_portal7.0.07.4.3.98
CVEListV5liferay/portal7.4.07.4.3.97
CVEListV5liferay/dxp7.3.107.3.10-u35+2

🔴Vulnerability Details

3
OSV
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature2025-10-27
GHSA
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature2025-10-27
CVEList
CVE-2025-62262: Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 72025-10-27
CVE-2025-62262 (MEDIUM CVSS 4.6) | Information exposure through log fi | cvebase.io