Description
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access all form entries.
Remediation
References
http://liferay.com
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42130
https://issues.liferay.com/browse/LPE-17447
Related Vulnerabilities
CVE-2019-10409 Vulnerability in maven package hudson.plugins:project-inheritance
CVE-2022-47937 Vulnerability in maven package org.apache.sling:org.apache.sling.commons.json
CVE-2019-7611 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2018-6341 Vulnerability in maven package org.webjars.bowergithub.vuejs:vue