An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
References
Link | Resource |
---|---|
http://liferay.com | Vendor Advisory |
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129 | Vendor Advisory |
https://issues.liferay.com/browse/LPE-17448 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-11-14 18:15
Updated : 2022-11-18 08:00
NVD link : CVE-2022-42129
Mitre link : CVE-2022-42129
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
liferay
- liferay_portal
- digital_experience_platform