An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access risks of other companies.
Link | Tags |
---|---|
https://www.deltarm.com | product vendor advisory |
https://gist.github.com/rntcruz23/6575c0ef45c30687c538361910bb8ab3 | third party advisory exploit |