Description


An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.

Related CPE's


a

liferay

digital_experience_platform

2

Weaknesses



CWE-639

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-15T01:15:11.590Z

3 years ago

Last modified

2025-04-30T17:15:51.447Z

10 months ago