CVE-2024-38447
EUVD-2024-3733617.07.2024, 18:15
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ncia | advisor_network | 3.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration