7.5
CVE-2021-33323
- EPSS 0.42%
- Veröffentlicht 03.08.2021 19:15:08
- Zuletzt bearbeitet 13.05.2025 18:17:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version7.1 Update-
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_10
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_11
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_12
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_13
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_14
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_15
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_16
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_17
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_18
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_3
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_4
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_5
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_6
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_7
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_8
Liferay ≫ Digital Experience Platform Version7.1 Updatefix_pack_9
Liferay ≫ Digital Experience Platform Version7.2 Update-
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_3
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_4
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_5
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_6
Liferay ≫ Liferay Portal Version >= 7.1.0 < 7.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.42% | 0.588 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.