CVE-2021-38268
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
El módulo Dynamic Data Mapping en Liferay Portal 7.0.0 hasta 7.3.6, y Liferay DXP 7.0 antes del fix pack 101, 7.1 antes del fix pack 21, 7.2 antes del fix pack 10 y 7.3 antes del fix pack 2 establece incorrectamente los permisos por defecto para los miembros del sitio, lo que permite a los usuarios remotos autentificados con el rol de miembro del sitio añadir y duplicar formularios, a través de la UI o la API
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-09 CVE Reserved
- 2022-03-02 CVE Published
- 2023-09-23 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | < 7.2.1 Search vendor "Liferay" for product "Digital Experience Platform" and version " < 7.2.1" | - |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_1 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_2 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_3 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_4 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_5 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_6 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_7 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_8 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.2 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2" | fix_pack_9 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.3 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.3" | - |
Affected
| ||||||
Liferay Search vendor "Liferay" | Digital Experience Platform Search vendor "Liferay" for product "Digital Experience Platform" | 7.3 Search vendor "Liferay" for product "Digital Experience Platform" and version "7.3" | fix_pack_1 |
Affected
| ||||||
Liferay Search vendor "Liferay" | Liferay Portal Search vendor "Liferay" for product "Liferay Portal" | >= 7.0.0 < 7.3.7 Search vendor "Liferay" for product "Liferay Portal" and version " >= 7.0.0 < 7.3.7" | community |
Affected
|