CVE-2025-62253

MEDIUM

Liferay Digital Experience Platform < 7.3 - Open Redirect

Title source: rule
STIX 2.1

Description

Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter.

Scores

CVSS v3 6.1
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (9)
com.liferay/com.liferay.layout.admin.web 5.0.8 - 5.0.157Maven
liferay/digital_experience_platform 7.3 (40 CPE variants)
liferay/digital_experience_platform 7.4
liferay/digital_experience_platform 2023.q3.1
liferay/digital_experience_platform 2023.q3.2
liferay/digital_experience_platform 2023.q3.3
liferay/digital_experience_platform 2023.q3.4
liferay/digital_experience_platform < 7.3
liferay/liferay_portal < 7.3.7
Published Oct 27, 2025
Tracked Since Feb 18, 2026