CVE-2024-38190
Published Oct 15, 2024Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
3 CVEs tagged to microsoft / power_platform — 1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Microsoft Power Platform Connector Spoofing Vulnerability