{"id":"CVE-2023-33948","details":"The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.","aliases":["BIT-liferay-2023-33948","GHSA-w6f8-mxf5-4vf8"],"modified":"2026-07-07T08:52:09.228427369Z","published":"2023-05-24T16:15:10.007Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.4-update67"},{"last_affected":"7.4-update67"}],"source":"CPE_STRING","vendor_product":"liferay:digital_experience_platform"}]},"references":[{"type":"ADVISORY","url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33948"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"93949a161f9e8bd8316028d26e11a74bdc53219b"},{"last_affected":"93949a161f9e8bd8316028d26e11a74bdc53219b"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:liferay:liferay_portal:7.4.3.67:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.4.3.67"},{"last_affected":"7.4.3.67"}]}}],"versions":["7.4.3.67","7.4.3.67-ga67"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-33948.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}