CVE-2024-35260

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*

History

03 Feb 2025, 15:15

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - Vendor Advisory
First Time Microsoft power Platform
Microsoft
CPE cpe:2.3:a:microsoft:power_platform:-:*:*:*:*:*:*:*

28 Dec 2024, 00:15

Type Values Removed Values Added
Summary (en) An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network. (en) An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

21 Nov 2024, 09:20

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 -

28 Jun 2024, 23:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de ejecución remota de código de Microsoft Dataverse
Summary (en) Microsoft Dataverse Remote Code Execution Vulnerability (en) An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network.

27 Jun 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 18:15

Updated : 2025-02-03 15:15


NVD link : CVE-2024-35260

Mitre link : CVE-2024-35260

CVE.ORG link : CVE-2024-35260


JSON object : View

Products Affected

microsoft

  • power_platform
CWE
CWE-426

Untrusted Search Path