Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv6f-5jw7-pmw8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
nvd
около 5 лет назад

In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-732