Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26176

Опубликовано: 18 дек. 2020
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document//attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tangro:business_workflow:*:*:*:*:*:*:*:*
Версия до 1.18.1 (исключая)

EPSS

Процентиль: 42%
0.00199
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-922

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.

EPSS

Процентиль: 42%
0.00199
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-922