CVE-2025-62266

CWE-601Open Redirect4 documents4 sources
Severity
5.1MEDIUM
EPSS
0.0%
top 87.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30

Description

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs. This vulnerability can be mitigated by changing the redirect URL security from IP to domain.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDliferay/liferay_portal7.4.07.4.3.110
Mavencom.liferay.portal:release.portal.bom7.4.0-ga17.4.3.110
CVEListV5liferay/portal7.4.07.4.3.119
CVEListV5liferay/dxp7.4.137.4.13-u92+3

🔴Vulnerability Details

3
CVEList
CVE-2025-62266: By default, Liferay Portal 72025-10-30
GHSA
Liferay Portal is vulnerable to DNS rebinding attacks2025-10-30
OSV
Liferay Portal is vulnerable to DNS rebinding attacks2025-10-30
CVE-2025-62266 (MEDIUM CVSS 5.1) | By default | cvebase.io