Description
The Dynamic Data Mapping module in Liferay Portal through v7.3.6 and Liferay DXP through v7.3 incorrectly sets default permissions for site members, allowing authenticated attackers to add and duplicate forms via the UI or the API.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-0631)
WordPress Plugin YITH Advanced Refund System for WooCommerce Security Bypass (1.0.10)
WordPress Plugin History Collection Arbitrary File Download (1.1.1)
WordPress Plugin Log Emails Information Disclosure (1.0.6)
WordPress Plugin Tooltipy (tooltips for WP) Multiple Vulnerabilities (5.0.2)