CVE-2025-62251

MEDIUM

Liferay Digital Experience Platform - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 11.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
com.liferay/com.liferay.site.navigation.menu.item.asset.vocabulary 0 - 1.0.23Maven
liferay/digital_experience_platform < 7.4
liferay/liferay_portal 7.3.0 - 7.4.3.119
Published Oct 13, 2025
Tracked Since Feb 18, 2026