TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-38268

MEDIUM
6.5

Description

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.

Details CVE

Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/2/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

liferay:digital_experience_platformliferay:liferay_portal

Faiblesses (CWE)

CWE-276

References

http://liferay.com(cve@mitre.org)
http://liferay.com(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.