Description


The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access all form entries.

Related CPE's


a

liferay

digital_experience_platform

46

Weaknesses



CWE-276

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-276

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-15T01:15:11.873Z

3 years ago

Last modified

2025-04-30T17:15:51.740Z

9 months ago