Vulnerability Description
An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access risks of other companies.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deltarm | Delta Rm | 1.2 |
References
- https://gist.github.com/rntcruz23/6575c0ef45c30687c538361910bb8ab3ExploitThird Party Advisory
- https://www.deltarm.comProductVendor Advisory
- https://gist.github.com/rntcruz23/6575c0ef45c30687c538361910bb8ab3ExploitThird Party Advisory
- https://www.deltarm.comProductVendor Advisory
FAQ
What is CVE-2021-44838?
CVE-2021-44838 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access ris...
How severe is CVE-2021-44838?
CVE-2021-44838 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44838?
Check the references section above for vendor advisories and patch information. Affected products include: Deltarm Delta Rm.