CVE-2025-62275

Severity
6.9MEDIUM
EPSS
0.1%
top 82.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1

Description

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDliferay/liferay_portal7.4.07.4.3.112
CVEListV5liferay/portal7.4.07.4.3.111
CVEListV5liferay/dxp7.4.137.4.13-u92+2

🔴Vulnerability Details

3
OSV
Liferay Portal and DXP do not check permissions of images in a blog entry2025-11-01
CVEList
CVE-2025-62275: Blogs in Liferay Portal 72025-11-01
GHSA
Liferay Portal and DXP do not check permissions of images in a blog entry2025-11-01
CVE-2025-62275 (MEDIUM CVSS 6.9) | Blogs in Liferay Portal 7.4.0 throu | cvebase.io