Looking for the vulnerability index of Invicti's legacy products?
Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2025-62242 - Vulnerability Database

Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2025-62242

Medium
Reference: CVE-2025-62242
Title: Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability
Overview:

Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111 and Liferay DXP 2023.Q4.0 through 2023.Q4.5 2023.Q3.1 through 2023.Q3.8 and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_admin_web_internal_portlet_AccountEntriesAdminPortlet_addressId parameter.