An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the /Home/GetAttachment function.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.nolanbkennedy.com/post/insecure-direct-object-reference-idor-in-xtivia-web-time-and-expense-webte | Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2019-12-06 03:15
Updated : 2020-08-24 17:37
NVD link : CVE-2019-19616
Mitre link : CVE-2019-19616
CVE.ORG link : CVE-2019-19616
JSON object : View
Products Affected
                xtivia
- web_time_and_expense
 
CWE
                
                    
                        
                        CWE-639
                        
            Authorization Bypass Through User-Controlled Key
