Miggo Logo

CVE-2025-62258: Liferay Portal Vulnerable to CSRF in Headless APIs

N/A

CVSS Score

Basic Information

EPSS Score
0.14846%
Published
10/28/2025
Updated
10/29/2025
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
com.liferay.portal:release.portal.bommaven>= 7.4.0-ga1, < 7.4.3.1087.4.3.108

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*SR* vuln*r**ility in ****l*ss *PI in Li**r*y Port*l *.*.* t*rou** *.*.*.***, *n* Li**r*y *XP ****.Q*.* t*rou** ****.Q*.*, *.* ** t*rou** up**t* **, *.* ** t*rou** up**t* **, *n* ol**r unsupport** v*rsions *llows r*mot* *tt**k*rs to *x**ut* *ny ****l

Reasoning

No *n*lysis *v*il**l*