CVE-2024-22455
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Feb 14, 2024
CWE ID 451
Summary
CVE-2024-22455 is a newly disclosed vulnerability affecting Dell E-Lab Navigator versions 3.1.9 and 3.2.0. This issue involves an Insecure Direct Object Reference (IDOR) in the Feedback submission feature. An attacker could exploit this vulnerability to manipulate the email's appearance, potentially deceiving recipients. Such exploitation could lead to reputational damage and security risks. This vulnerability may allow unauthorized access or modification of data, posing a threat to users' trust and security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.