Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance via the comliferayusersadminwebportletUsersAdminPortletaddUserIds parameter.
{ "cwe_ids": [ "CWE-639" ], "nvd_published_at": "2025-10-13T21:15:35Z", "github_reviewed_at": "2025-10-13T23:12:07Z", "github_reviewed": true, "severity": "MODERATE" }