ZeroHour

CVE-2020-26178

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p58
Published
()
Modified
Description

In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

Vendors
tangro
Products
business workflow
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.