Description
The Dynamic Data Mapping module in Liferay Portal through v7.3.6 and Liferay DXP through v7.3 incorrectly sets default permissions for site members, allowing authenticated attackers to add and duplicate forms via the UI or the API.
Remediation
References
Related Vulnerabilities
WordPress Plugin Import and export users and customers Cross-Site Request Forgery (1.14.1.3)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5593)
Oracle Database Server CVE-2019-2776 Vulnerability (CVE-2019-2776)
Check for apache versions up to 1.3.25, 2.0.38
WordPress Plugin Data Tables Generator by Supsystic Multiple Vulnerabilities (1.9.91)