Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
7.4.0 (maven)
affected
Default status
unaffected
7.3.10 (maven)
affected
7.4.13 (maven)
affected
2023.Q3.1 (maven)
affected
Description
Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
Problem types
CWE-863 Incorrect Authorization
Product status
7.4.0 (maven)
7.3.10 (maven)
7.4.13 (maven)
2023.Q3.1 (maven)
Credits
4rth4s
References
liferay.dev/...-/asset_publisher/jekt/content/CVE-2025-62259
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.