Junglewise Threat Intelligence

CVE-2025-62242: Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key

CVE-2025-62242 · Severity: medium · CVSS 4 · Published 2025-10-13

Technologies: com.liferay:com.liferay.change.tracking.web (Maven). Vendors: Maven.

Executive brief

Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key

Affected products

  • Maven com.liferay:com.liferay.change.tracking.web

Related threats