Tangro
Tangro Business Workflow: vulnerabilidades y CVE
Tangro Business Workflow tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-26178 | Media (5.3) | 0.90% | — | 18 dic 2020 | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated. |
| CVE-2020-26177 | Media (4.3) | 0.65% | — | 18 dic 2020 | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side.… |
| CVE-2020-26176 | Media (4.3) | 0.75% | — | 18 dic 2020 | An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all… |
| CVE-2020-26175 | Media (6.5) | 0.67% | — | 18 dic 2020 | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users. |
| CVE-2020-26174 | Alta (8.8) | 1.2% | — | 18 dic 2020 | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser… |
| CVE-2020-26173 | Media (4.3) | 0.74% | — | 18 dic 2020 | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required. |
| CVE-2020-26172 | Media (6.5) | 0.66% | — | 18 dic 2020 | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp. |
| CVE-2020-26171 | Media (4.3) | 0.58% | — | 18 dic 2020 | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them. |