Vulnerability Details CVE-2022-42129
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.8%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2022-42129
-
cpe:2.3:a:liferay:digital_experience_platform:7.3
-
cpe:2.3:a:liferay:digital_experience_platform:7.4
-
cpe:2.3:a:liferay:liferay_portal:7.3.2
-
cpe:2.3:a:liferay:liferay_portal:7.3.3
-
cpe:2.3:a:liferay:liferay_portal:7.3.4
-
cpe:2.3:a:liferay:liferay_portal:7.3.5
-
cpe:2.3:a:liferay:liferay_portal:7.3.6
-
cpe:2.3:a:liferay:liferay_portal:7.3.7
-
cpe:2.3:a:liferay:liferay_portal:7.4.0
-
cpe:2.3:a:liferay:liferay_portal:7.4.1
-
cpe:2.3:a:liferay:liferay_portal:7.4.2
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.4