First published: Wed Mar 02 2022(Updated: )
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay Digital Experience Platform | <7.2.1 | |
Liferay Digital Experience Platform | =7.2-fix_pack_1 | |
Liferay Digital Experience Platform | =7.2-fix_pack_2 | |
Liferay Digital Experience Platform | =7.2-fix_pack_3 | |
Liferay Digital Experience Platform | =7.2-fix_pack_4 | |
Liferay Digital Experience Platform | =7.2-fix_pack_5 | |
Liferay Digital Experience Platform | =7.2-fix_pack_6 | |
Liferay Digital Experience Platform | =7.2-fix_pack_7 | |
Liferay Digital Experience Platform | =7.2-fix_pack_8 | |
Liferay Digital Experience Platform | =7.2-fix_pack_9 | |
Liferay Digital Experience Platform | =7.3 | |
Liferay Digital Experience Platform | =7.3-fix_pack_1 | |
Liferay Liferay Portal | >=7.0.0<7.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38268 is a vulnerability in Liferay Portal and Liferay DXP that allows remote authenticated users with site member permissions to add new forms by default.
CVE-2021-38268 has a severity level of medium (CVSS score of 6.5).
CVE-2021-38268 affects Liferay Portal versions 7.0.0 through 7.3.6, and Liferay DXP versions 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10, and 7.3 before fix pack 2.
Remote authenticated users with site member permissions can exploit CVE-2021-38268 by adding new forms by default.
You can find more information about CVE-2021-38268 on the Liferay website and the Liferay Developer Portal.