Looking for the vulnerability index of Invicti's legacy products?
Liferay DXP Improper Restriction of Excessive Authentication Attempts Vulnerability - CVE-2025-62257 - Vulnerability Database

Liferay DXP Improper Restriction of Excessive Authentication Attempts Vulnerability - CVE-2025-62257

Medium
Reference: CVE-2025-62257
Title: Liferay DXP Improper Restriction of Excessive Authentication Attempts Vulnerability
Overview:

Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119 and older unsupported versions and Liferay DXP 2024.Q1.1 through 2024.Q1.5 2023.Q4.0 through 2023.Q4.10 2023.Q3.1 through 2023.Q3.10 7.4 GA through update 92 and older unsupported versions allows remote attackers to determine a users password even if account lockout is enabled via brute force attack.