4
CVSSv2

CVE-2019-19616

Published: 06/12/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV prior to 2017 allows an malicious user to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the /Home/GetAttachment function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xtivia web time and expense