CVE-2025-62261

Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.
CVSS

No CVSS.

Configurations

No configuration.

History

27 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 22:15

Updated : 2025-10-30 15:05


NVD link : CVE-2025-62261

Mitre link : CVE-2025-62261

CVE.ORG link : CVE-2025-62261


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information