CVE-2025-62245
Liferay Portal is vulnerable to CSRF through publication comments
EPSS 0.01%
Description
Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments.
How to fix CVE-2025-62245
To remediate CVE-2025-62245, upgrade the affected package to a fixed version below.
- Maven/com.liferay:com.liferay.change.tracking.web—upgrade to 2.0.121 or later
Is CVE-2025-62245 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.9, < 2.0.121
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |