Liferay DXP Incorrect Default Permissions Vulnerability - CVE-2022-42130 - Vulnerability Database

Liferay DXP Incorrect Default Permissions Vulnerability - CVE-2022-42130

Medium
Reference: CVE-2022-42130
Title: Liferay DXP Incorrect Default Permissions Vulnerability
Overview:

The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4 and Liferay DXP 7.1 before fix pack 27 7.2 before fix pack 19 7.3 before update 4 and 7.4 GA does not properly check permission of form entries which allows remote authenticated users to view and access all form entries.