Liferay Portal and Liferay DXP Publications Portlet Insecure Direct Object Reference Vulnerability

Vulnerability

An insecure direct object reference (IDOR) vulnerability has been identified in the Publications feature of Liferay Portal versions 7.4.1 through 7.4.3.112, as well as in Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92. This vulnerability allows remote authenticated attackers to view and edit publication comments. The issue arises because the Publications Portlet does not properly validate user permissions, enabling remote authenticated users to manipulate comments through crafted URLs.

Impact

Exploitation of this vulnerability allows remote authenticated users to bypass permission checks and gain unauthorized access to publication comments, including the ability to edit them.

Remediation

Users can upgrade to Liferay Portal 7.4.3.113 or Liferay DXP versions 2024.Q2.0, 2024.Q1.1, 2023.Q4.6, or 2023.Q3.9 to address this vulnerability.

Added: Oct 13, 2025, 6:17 PM
Updated: Oct 13, 2025, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
4.8
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.