Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_admin_web_internal_portlet_AccountEntriesAdminPortlet_addressId parameter.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3cm9-jrf5-h2cx Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 13 Oct 2025 19:30:00 +0000

Type Values Removed Values Added
Description Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_admin_web_internal_portlet_AccountEntriesAdminPortlet_addressId parameter.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published:

Updated: 2025-10-13T19:10:30.348Z

Reserved: 2025-10-09T20:58:49.217Z

Link: CVE-2025-62242

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-13T20:15:34.243

Modified: 2025-10-13T20:15:34.243

Link: CVE-2025-62242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.