CVE-2022-42129
published 2022-11-15CVE-2022-42129: An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.59%
44.5th percentile
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | >= 7.3.2 < 7.4.3.5 | 7.4.3.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Dynamic Data Mapping formInstanceRecordId resource injection
vuldb·2026-07-08·CVSS 4.3
CVE-2022-42129 [MEDIUM] Liferay Portal/DXP Dynamic Data Mapping formInstanceRecordId resource injection
A vulnerability marked as critical has been reported in Liferay Portal and DXP. The affected element is an unknown function of the component Dynamic Data Mapping Module. This manipulation of the argument formInstanceRecordId causes improper control of resource identifiers.
This vulnerability is tracked as CVE-2022-42129. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
OSV
Authorization Bypass in Liferay Portal
osv·2022-11-15
CVE-2022-42129 [MEDIUM] Authorization Bypass in Liferay Portal
Authorization Bypass in Liferay Portal
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
GHSA
Authorization Bypass in Liferay Portal
ghsa·2022-11-15
CVE-2022-42129 [MEDIUM] CWE-639 Authorization Bypass in Liferay Portal
Authorization Bypass in Liferay Portal
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17448https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129https://issues.liferay.com/browse/LPE-17448https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129
2022-11-15
Published