{"id":"CVE-2025-62245","details":"Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments.","aliases":["GHSA-9676-rh83-cr86"],"modified":"2026-09-05T03:30:29.037213877Z","published":"2025-10-10T20:15:39.373Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"2023.Q3.1"},{"last_affected":"2023.Q3.10"},{"introduced":"2023.q4.0"},{"fixed":"2023.q4.6"}],"source":"CPE_RANGE","vendor_product":"liferay:digital_experience_platform","cpes":["cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*"]},{"source":"CPE_STRING","vendor_product":"liferay:digital_experience_platform","cpes":["cpe:2.3:a:liferay:digital_experience_platform:7.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.4"},{"last_affected":"7.4"}]}]},"references":[{"type":"ADVISORY","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62245"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"548f3899675d89749f92b7623d25e27d0c4691c7"},{"fixed":"99206814748a429237e8d56ece5f9c5a8221c4d3"}],"database_specific":{"cpe":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.4.1"},{"fixed":"7.4.3.113"}],"source":"CPE_RANGE"}}],"versions":["7.4.3.88-ga88","7.4.3.41-ga41","7.4.3.7-ga7","7.4.3.6-ga6","7.4.3.5-ga5","7.4.3.4-ga4","7.4.2-ga3","7.4.1-ga2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62245.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}