Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-26171

    In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020

    CVE-2020-26172

    Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020

    CVE-2020-26173

    An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020

    CVE-2020-26174

    tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a workitem.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020

    CVE-2020-26175

    In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020
    Items Per Page
    Tangro Vulnerabilities & Security CVEs | CVE-DB