CVE-2024-46635
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
Published 2024-09-30. Last modified 2026-06-17.