ZeroHour

CVE-2022-39038

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
Description

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.

Vendors
flowring
Products
agentflow
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.