Description
The Dynamic Data Mapping module in Liferay Portal through v7.3.6 and Liferay DXP through v7.3 incorrectly sets default permissions for site members, allowing authenticated attackers to add and duplicate forms via the UI or the API.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 International Sms Integration Cross-Site Scripting (1.2)
Atlassian Jira Insufficient Session Expiration Vulnerability (CVE-2021-39113)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3126)
WordPress Plugin Nokia Maps & Places Cross-Site Scripting (1.6.6)