Vulnerabilities > CVE-2020-26176 - Insecure Storage of Sensitive Information vulnerability in Tangro Business Workflow 1.17.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |