
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62275 is an incorrect authorization vulnerability in the Blogs component of Liferay Portal and Liferay DXP that allows unauthenticated remote attackers to view restricted images in blog entries via a crafted URL. It affects Liferay Portal versions 7.4.0 through 7.4.3.111 (and older unsupported versions), and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 (and older unsupported versions). The vulnerability was disclosed on November 1, 2025, with NVD initial analysis completed on November 10, 2025. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Liferay Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): the Blogs module in affected Liferay versions fails to perform permission checks when serving images embedded in blog entries. An attacker can construct a crafted URL pointing directly to a blog entry image resource, bypassing the access control logic that would normally restrict visibility based on the blog entry's permissions. No authentication, special privileges, or user interaction is required to exploit this flaw. The vulnerable Maven package is com.liferay:com.liferay.blogs.item.selector.web, with versions below 6.0.19 affected; the fix was introduced in version 6.0.19 (GitHub Advisory, Liferay Advisory).
Successful exploitation results in unauthorized disclosure of images embedded in blog entries that should be restricted to specific users or roles. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive or private visual content (e.g., internal documents, proprietary diagrams, or personal images) could be exposed to any unauthenticated internet user. The vulnerability does not enable lateral movement, code execution, or data modification, but it may contribute to broader information disclosure in environments where blog entries contain sensitive imagery (GitHub Advisory, Liferay Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.058% (18th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is straightforward in concept — requiring only a crafted URL with no authentication — but the limited impact (image disclosure only) reduces attacker incentive (GitHub Advisory).
/documents/, /image/, or blog-related image paths) originating from external or unexpected IP addresses, particularly without a valid session cookie.JSESSIONID or equivalent session token); high volume of image resource requests from a single IP or user agent.Liferay has released patches addressing this vulnerability. Users should upgrade the com.liferay:com.liferay.blogs.item.selector.web Maven package to version 6.0.19 or later. For Liferay Portal, upgrade to version 7.4.3.112 or later; for Liferay DXP, upgrade beyond 2023.Q4.10 or 2023.Q3.10 to a fixed quarterly release. As interim mitigations, administrators should implement additional network-level access controls (e.g., WAF rules or reverse proxy authentication) for blog image endpoints, audit existing blog entries for sensitive images, and monitor access logs for unauthorized image retrieval attempts (GitHub Advisory, Liferay Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."