
Cloud Vulnerability DB
A community-led vulnerabilities database
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, contains a permission check vulnerability. This vulnerability was disclosed in 2021 and affects multiple versions of Liferay Portal and Liferay DXP products (NVD).
The vulnerability stems from improper permission checking in the Dynamic Data Mapping module. The issue specifically affects the forms section in site administration, where the system fails to properly validate user permissions. The vulnerability has been assigned a CVSS v3.1 Base Score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).
When exploited, this vulnerability allows remote attackers with the forms 'Access in Site Administration' permission to view all forms and form entries in a site via the forms section in site administration. This represents an unauthorized access to potentially sensitive form data (NVD).
The vulnerability has been addressed in various versions of Liferay products. Users should upgrade to Liferay DXP 7.0 fix pack 94 or later, 7.1 fix pack 19 or later, or 7.2 fix pack 6 or later. For Liferay Portal users, versions after 7.3.2 contain the fix (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."