CVE-2025-62251

Source
https://cve.org/CVERecord?id=CVE-2025-62251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62251
Aliases
Published
2025-10-13T22:15:32.897Z
Modified
2026-07-08T07:32:10.262295923Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "liferay:digital_experience_platform",
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "last_affected": "7.4"
                },
                {
                    "introduced": "2023.q3.1"
                },
                {
                    "fixed": "2023.q3.9"
                },
                {
                    "introduced": "2023.q4.0"
                },
                {
                    "fixed": "2023.q4.6"
                }
            ],
            "cpes": [
                "cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/liferay/liferay-portal

Affected ranges

Type
GIT
Repo
https://github.com/liferay/liferay-portal
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.3.0"
        },
        {
            "fixed": "7.4.3.119"
        }
    ]
}

Affected versions

7.*
7.3.0-ga1
7.3.1-ga2
7.3.2-ga3
7.3.3-ga4
7.3.4-ga5
7.3.5-ga6
7.4.0-ga1
7.4.1-ga2
7.4.2-ga3
7.4.3.118-ga118
7.4.3.4-ga4
7.4.3.41-ga41
7.4.3.5-ga5
7.4.3.6-ga6
7.4.3.7-ga7
7.4.3.88-ga88
Other
test-fix-pack-base-7310

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62251.json"