PT-2025-41802 · Liferay · Liferay Dxp

·

CVE-2025-62241

·

Published

2025-10-13

·

Updated

2025-10-13

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Liferay DXP versions 2023.Q4.1 through 2023.Q4.5
Description An Insecure Direct Object Reference (IDOR) issue exists in Liferay DXP that allows authenticated remote users to access shipment addresses from different virtual instances. This occurs through the commerceOrderId parameter in the com liferay commerce order web internal portlet CommerceOrderPortlet component.
Recommendations Update Liferay DXP versions prior to 2023.Q4.6.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62241
GHSA-FHCW-PX4Q-PMVV

Affected Products

Liferay Dxp