Description
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
References
Vendor Advisory
https://issues.liferay.com/browse/LPE-17448
Vendor Advisory
Vendor Advisory
https://issues.liferay.com/browse/LPE-17448
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-15T01:15:11.590Z
3 years agoLast modified
2025-04-30T17:15:51.447Z
10 months ago