An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-11-15T00:00:00

Updated: 2022-11-15T00:00:00

Reserved: 2022-10-03T00:00:00


Link: CVE-2022-42129

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-11-15T02:15:11.590

Modified: 2022-11-18T16:00:17.067


Link: CVE-2022-42129

JSON object: View

cve-icon Redhat Information

No data.

CWE