4
CVSSv2

CVE-2020-26171

Published: 18/12/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

In tangro Business Workflow prior to 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tangro business workflow