7
CVE-2025-62258
- EPSS 0.02%
- Veröffentlicht 27.10.2025 22:56:21
- Zuletzt bearbeitet 10.11.2025 21:39:01
- Quelle security@liferay.com
- CVE-Watchlists
- Unerledigt
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version7.3 Update-
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate16
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate17
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate18
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate19
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate20
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate21
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate22
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate23
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate24
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate25
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate26
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate27
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate28
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate29
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate30
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate31
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate32
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate33
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate34
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate35
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate9
Liferay ≫ Digital Experience Platform Version7.4
Liferay ≫ Digital Experience Platform Version2023.q3.1
Liferay ≫ Digital Experience Platform Version2023.q3.2
Liferay ≫ Digital Experience Platform Version2023.q3.3
Liferay ≫ Digital Experience Platform Version2023.q3.4
Liferay ≫ Liferay Portal Version >= 7.4.0 < 7.4.3.108
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| security@liferay.com | 7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.