Liferay Portal and Liferay DXP has incorrect default permissions for site members
Moderate severity
GitHub Reviewed
Published
Mar 3, 2022
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Package
Affected versions
>= 7.0.0, < 7.0.10.fp101
>= 7.1.0, < 7.1.10.fp21
>= 7.2.0, < 7.2.10.fp10
>= 7.3.0, < 7.3.10.fp2
Patched versions
7.0.10.fp101
7.1.10.fp21
7.2.10.fp10
7.3.10.fp2
Description
Published by the National Vulnerability Database
Mar 2, 2022
Published to the GitHub Advisory Database
Mar 3, 2022
Reviewed
Jul 14, 2025
Last updated
Jul 14, 2025
The Dynamic Data Mapping module before 4.0.39 from Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
References