An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 | vendor advisory |