CVE-2019-19616: Xtivia Web Time And Expense

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the /Home/GetAttachment function.

Affected products

  • Xtivia Web Time And Expense: before 2017 (fixed in 2017)

Published 2019-12-06. Last modified 2026-06-17.