4
CVSSv2

CVE-2020-26176

Published: 18/12/2020 Updated: 21/12/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An issue exists in tangro Business Workflow prior to 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the malicious user to gather valid attachment IDs for workitems that do not belong to them.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tangro business workflow