Executive brief
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
Affected products
- Maven com.liferay.portal:com.liferay.portal.kernel
Junglewise Threat Intelligence
CVE-2025-3526 · Severity: medium · CVSS 4 · Published 2025-06-16
Technologies: com.liferay.portal:com.liferay.portal.kernel (Maven). Vendors: Maven.
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session