CVE-2024-22455

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Feb 14, 2024
CWE ID 451

Summary

CVE-2024-22455 is a newly disclosed vulnerability affecting Dell E-Lab Navigator versions 3.1.9 and 3.2.0. This issue involves an Insecure Direct Object Reference (IDOR) in the Feedback submission feature. An attacker could exploit this vulnerability to manipulate the email's appearance, potentially deceiving recipients. Such exploitation could lead to reputational damage and security risks. This vulnerability may allow unauthorized access or modification of data, posing a threat to users' trust and security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share