Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xf7m-v66q-76w8 Liferay Portal and DXP do not check permissions of images in a blog entry
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Liferay digital Experience Platform
Liferay liferay Portal
CPEs cpe:2.3:a:liferay:digital_experience_platform:2023.q3.10:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.2:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.3:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.4:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.5:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.6:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.7:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.8:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.9:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.10:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.2:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.3:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.4:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.5:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.6:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.7:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.8:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.9:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Vendors & Products Liferay digital Experience Platform
Liferay liferay Portal
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 03 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Liferay
Liferay dxp
Liferay portal
Vendors & Products Liferay
Liferay dxp
Liferay portal

Sat, 01 Nov 2025 03:00:00 +0000

Type Values Removed Values Added
Description Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published:

Updated: 2025-11-03T15:47:50.284Z

Reserved: 2025-10-09T20:58:54.403Z

Link: CVE-2025-62275

cve-icon Vulnrichment

Updated: 2025-11-03T15:47:47.635Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-01T03:15:31.757

Modified: 2025-11-10T16:20:40.737

Link: CVE-2025-62275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-03T10:43:45Z