Description
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
Remediation
References
http://liferay.com
https://issues.liferay.com/browse/LPE-17448
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129
Related Vulnerabilities
CVE-2014-4611 Vulnerability in maven package net.jpountz.lz4:lz4
CVE-2023-43498 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-18353 Vulnerability in npm package rendertron-middleware
CVE-2019-11777 Vulnerability in maven package org.eclipse.paho:org.eclipse.paho.client.mqttv3
CVE-2020-27220 Vulnerability in maven package org.eclipse.hono:hono-adapter-mqtt-vertx-base