The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-08-03T18:19:24
Updated: 2024-08-03T23:50:41.443Z
Reserved: 2021-05-20T00:00:00
Link: CVE-2021-33323
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-03T19:15:08.657
Modified: 2024-11-21T06:08:41.367
Link: CVE-2021-33323
Redhat
No data.