CVE-2021-38268 Site member can add new forms by default

Description

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.

Severity

Severity 2

Fixed Version(s)

There is no fix available for Liferay Portal 7.0 and 7.1. Please upgrade to Liferay Portal 7.3.

Publication date: Mon, 30 Aug 2021 16:00:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.