CVE-2025-62266 Details
Description
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs. This vulnerability can be mitigated by changing the redirect URL security from IP to domain.
A vulnerability exists in Liferay Portal versions 7.4.0 to 7.4.3.119, older unsupported versions, and Liferay DXP versions 2024.Q1.1 to 2024.Q1.5, 2023.Q4.0 to 2023.Q4.10, 2023.Q3.1 to 2023.Q3.10, and 7.4 GA through update 92. This vulnerability allows for DNS rebinding attacks, where remote attackers can redirect users to arbitrary external URLs. The issue arises because the default security settings for redirect URLs can be manipulated. To exploit this vulnerability, an attacker could potentially craft a URL that takes advantage of the DNS rebinding technique, redirecting users to a malicious site or resource.
Users can mitigate this vulnerability by changing the redirect URL security from IP to domain.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62256 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| liferay digital experience platform | 7.3 - 7.3 fix_pack_1 7.3 fix_pack_2 7.3 service_pack_1 7.3 service_pack_2 7.3 service_pack_3 7.3 update1 7.3 update10 7.3 update11 7.3 update12 7.3 update13 7.3 update14 7.3 update15 7.3 update16 7.3 update17 7.3 update18 7.3 update19 7.3 update2 7.3 update20 7.3 update21 7.3 update22 7.3 update23 7.3 update24 7.3 update25 7.3 update26 7.3 update27 7.3 update28 7.3 update29 7.3 update3 7.3 update30 7.3 update31 7.3 update32 7.3 update33 7.3 update34 7.3 update35 7.4 - 7.4 update1 7.4 update10 7.4 update11 7.4 update12 7.4 update13 7.4 update14 7.4 update15 7.4 update16 7.4 update17 7.4 update18 7.4 update19 7.4 update2 7.4 update20 7.4 update21 7.4 update22 7.4 update23 7.4 update24 7.4 update25 7.4 update26 7.4 update27 7.4 update28 7.4 update29 7.4 update3 7.4 update30 7.4 update31 7.4 update32 7.4 update33 7.4 update34 7.4 update35 7.4 update36 7.4 update37 7.4 update38 7.4 update39 7.4 update4 7.4 update40 7.4 update41 7.4 update42 7.4 update43 7.4 update44 7.4 update45 7.4 update46 7.4 update47 7.4 update48 7.4 update49 7.4 update5 7.4 update50 7.4 update51 7.4 update52 7.4 update53 7.4 update54 7.4 update55 7.4 update56 7.4 update57 7.4 update58 7.4 update59 7.4 update6 7.4 update60 7.4 update61 7.4 update62 7.4 update63 7.4 update64 7.4 update65 7.4 update66 7.4 update67 7.4 update68 7.4 update69 7.4 update7 7.4 update70 7.4 update71 7.4 update72 7.4 update73 7.4 update74 7.4 update75 7.4 update76 7.4 update77 7.4 update78 7.4 update79 7.4 update8 7.4 update80 7.4 update81 7.4 update82 7.4 update83 7.4 update84 7.4 update85 7.4 update86 7.4 update87 7.4 update88 7.4 update89 7.4 update9 7.4 update90 7.4 update91 7.4 update92 2023.q3.1 2023.q3.2 2023.q3.3 2023.q3.4 2023.q3.5 2023.q3.6 2023.q3.7 2023.q4.0 2023.q4.1 2023.q4.2 2023.q4.3 2023.q4.4 2023.q4.5 |
CPE
Remediation
| |
| liferay liferay portal | >= 7.4.0, < 7.4.3.110 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 11, 2025 | Initial Analysis | [email protected] |
| Oct 30, 2025 | CVE Modified | [email protected] |
| Oct 30, 2025 | New CVE Received | [email protected] |