Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhrf-h3r9-63x8

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

EPSS

Процентиль: 7%
0.00028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 5.4
nvd
30 дней назад

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

EPSS

Процентиль: 7%
0.00028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288