CVE-2024-35260

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*

History

03 Feb 2025, 15:15

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*
First Time Microsoft power Platform
Microsoft
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - Vendor Advisory

28 Dec 2024, 00:15

Type Values Removed Values Added
Summary (en) An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network. (en) An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

Information

Published : 2024-06-27 18:15

Updated : 2025-02-03 15:15


NVD link : CVE-2024-35260

Mitre link : CVE-2024-35260

CVE.ORG link : CVE-2024-35260


JSON object : View

Products Affected

microsoft

  • power_platform
CWE
CWE-426

Untrusted Search Path