Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42130


The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access all form entries.


Published

2022-11-15T02:15:11.873

Last Modified

2025-04-30T19:15:51.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-276
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.1 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.2 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay liferay_portal < 7.4.3.5 Yes

References