---
id: CVE-2022-25146
title: >-
  The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through
  v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of
  event messages it receives matches the origin of the Remote App, allowing
  attackers to e…
summary: >-
  The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through
  v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of
  event messages it receives matches the origin of the Remote App, allowing
  attackers to e…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-346
vendor: liferay
product: digital_experience_platform
affected:
  - digital_experience_platform <= 7.4
  - 'liferay_portal >= 7.4.3.4, < 7.4.3.9'
patched:
  - liferay_portal 7.4.3.9
published: '2022-03-03'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-25146'
references:
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps
    label: cve@mitre.org
  - url: 'https://www.securitum.pl'
    label: cve@mitre.org
  - url: 'http://liferay.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.securitum.pl'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00452
epssPercentile: 0.36775
ingestedAt: '2026-07-06T17:03:23.932Z'
---

## Overview

The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.

## Affected

- `digital_experience_platform <= 7.4`
- `liferay_portal >= 7.4.3.4, < 7.4.3.9`

## Remediation

Upgrade past the affected range:

- `liferay_portal 7.4.3.9`
