CVE-2025-3639 is an authentication bypass vulnerability in Liferay Portal and Liferay DXP affecting Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92, and 7.3 GA through update 36. According to the provided description, when multi-factor authentication (MFA) is enabled, an attacker with valid user credentials can bypass the normal login process by changing the request method from POST to GET. This indicates improper enforcement of the intended authentication flow, allowing the application to accept an alternate request path that does not correctly require completion of MFA before establishing an authenticated session.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Proof of Concept (PoC) exploit for CVE-2025-3639, a login bypass vulnerability affecting Liferay Portal (versions 7.3.0–7.4.3.132) and Liferay DXP (2024.Q1 to 2025.Q1.6). The exploit demonstrates that an attacker with valid credentials can bypass multi-factor authentication (MFA) by sending a crafted HTTP GET request (instead of the expected POST) to the /c/portal/login endpoint. The repository contains two files: a detailed README.md explaining the vulnerability, usage, and requirements, and poc.py, a Python script that performs the exploit. The script takes the target URL, username, and password as arguments, sends the GET request, and checks for a valid session token in the response cookies. If successful, it prints the session token, indicating unauthorized access to the user account without completing MFA. The exploit is a network-based attack and requires valid credentials but does not require prior authentication. No hardcoded endpoints or IPs are present; the target is user-supplied. The repository is structured as a simple PoC for educational and testing purposes.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.