4.0.182
6 years ago
15 days ago
Known vulnerabilities in the com.liferay:com.liferay.dynamic.data.mapping.form.web package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.liferay:com.liferay.dynamic.data.mapping.form.web is a Liferay Dynamic Data Mapping Form Web. Affected versions of this package are vulnerable to Uninitialized Memory Exposure due to insufficient permission checks in the How to fix Uninitialized Memory Exposure? Upgrade | [,4.0.174) |
com.liferay:com.liferay.dynamic.data.mapping.form.web is a Liferay Dynamic Data Mapping Form Web. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in Form widget configuration allowing remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's How to fix Cross-site Scripting (XSS)? Upgrade | [,3.0.6) |
com.liferay:com.liferay.dynamic.data.mapping.form.web is a Liferay Dynamic Data Mapping Form Web. Affected versions of this package are vulnerable to Information Exposure due to insecure direct object reference (IDOR), accessible via the Dynamic Data Mapping module's How to fix Information Exposure? Upgrade | [,4.0.55) |
com.liferay:com.liferay.dynamic.data.mapping.form.web is a Liferay Dynamic Data Mapping Form Web. Affected versions of this package are vulnerable to Improper Authorization. It autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user. How to fix Improper Authorization? Upgrade | [,3.0.23) |
com.liferay:com.liferay.dynamic.data.mapping.form.web is a Liferay Dynamic Data Mapping Form Web. Affected versions of this package are vulnerable to Improper Authorization. It does not properly check user permissions, which allows remote attackers with How to fix Improper Authorization? Upgrade | [,3.0.21) |