Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42129


An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.


Published

2022-11-15T02:15:11.590

Last Modified

2025-04-30T19:15:51.447

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-639
  • Type: Secondary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay liferay_portal < 7.4.3.5 Yes

References