Improper Default Permissions in Liferay Portal and DXP by Liferay
CVE-2021-38268

6.5MEDIUM

Key Information:

Vendor

Liferay

Vendor
CVE Published:
2 March 2022

What is CVE-2021-38268?

The Dynamic Data Mapping module in Liferay Portal and DXP allows remote authenticated users with the site member role to incorrectly access and manipulate forms due to improperly configured default permissions. Users can add and duplicate forms via both the user interface and the API, potentially leading to unauthorized alterations within the application.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.