Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 10 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments. | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Liferay
Published: 2025-10-10T19:12:11.245Z
Updated: 2025-10-10T20:25:59.228Z
Reserved: 2025-10-09T20:58:49.217Z
Link: CVE-2025-62245

Updated: 2025-10-10T20:25:52.248Z

Status : Received
Published: 2025-10-10T20:15:39.373
Modified: 2025-10-10T20:15:39.373
Link: CVE-2025-62245

No data.