The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
{
"unresolved_ranges": [
{
"vendor_product": "liferay:digital_experience_platform",
"extracted_events": [
{
"last_affected": "7.4-update67"
}
],
"cpes": [
"cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "7.4.3.67"
}
],
"cpe": "cpe:2.3:a:liferay:liferay_portal:7.4.3.67:*:*:*:*:*:*:*",
"source": "CPE_STRING"
}