Liferay Portal Incorrect Default Permissions Vulnerability - CVE-2021-33334 - Vulnerability Database

Liferay Portal Incorrect Default Permissions Vulnerability - CVE-2021-33334

Medium
Reference: CVE-2021-33334
Title: Liferay Portal Incorrect Default Permissions Vulnerability
Overview:

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2 and Liferay DXP 7.0 before fix pack 94 7.1 before fix pack 19 and 7.2 before fix pack 6 does not properly check user permissions which allows remote attackers with the forms quotAccess in Site Administrationquot permission to view all forms and form entries in a site via the forms section in site administration.