Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay/com.liferay.change.tracking.web
  4. ›
  5. CVE-2025-62242

CVE-2025-62242: Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key

October 13, 2025

Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_admin_web_internal_portlet_AccountEntriesAdminPortlet_addressId parameter.

References

  • github.com/advisories/GHSA-3cm9-jrf5-h2cx
  • github.com/liferay/liferay-portal
  • github.com/liferay/liferay-portal/commit/dd89fff675f04d146fda38a1bec884cf40d0c756
  • github.com/liferay/liferay-portal/commit/fa356d07ab239e790b7e460d33c25184aef58716
  • liferay.atlassian.net/browse/LPE-17932
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62245
  • nvd.nist.gov/vuln/detail/CVE-2025-62242

Code Behaviors & Features

Detect and mitigate CVE-2025-62242 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.0.120

Fixed versions

  • 2.0.120

Solution

Upgrade to version 2.0.120 or above.

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

maven/com.liferay/com.liferay.change.tracking.web/CVE-2025-62242.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 07 Nov 2025 00:18:57 +0000.