CVE Database
/

CVE-2025-62261

Back to search

CVE-2025-62261

Published: Oct 27, 2025

Modified: Oct 28, 2025

PUBLISHED

Description

Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.

VendorProductVersions

Liferay

Portal

affected
7.4.0 - <= 7.4.3.99

Liferay

DXP

affected
7.3.10 - <= 7.3.10-u34
affected
7.4.13 - <= 7.4.13-u92
affected
2023.Q3.1 - <= 2023.Q3.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now