An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access risks of other companies.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Delta_rm | Deltarm | 1.2 (including) | 1.2 (including) |