Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Mon, 27 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account. | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published: 2025-10-27T21:11:46.893Z
Updated: 2025-10-28T14:27:47.375Z
Reserved: 2025-10-09T20:58:53.011Z
Link: CVE-2025-62261
Updated: 2025-10-28T14:27:44.713Z
Status : Received
Published: 2025-10-27T22:15:41.733
Modified: 2025-10-27T22:15:41.733
Link: CVE-2025-62261
No data.