Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2022-42129 - Vulnerability Database

Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2022-42129

Medium
Reference: CVE-2022-42129
Title: Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability
Overview:

An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.3 before update 4 and 7.4 GA allows remote authenticated users to view and access form entries via the formInstanceRecordId parameter.