Vulnerabilities > Tangro > Business Workflow > 1.17.5

DATE CVE VULNERABILITY TITLE RISK
2020-12-18 CVE-2020-26177 Incorrect Permission Assignment for Critical Resource vulnerability in Tangro Business Workflow 1.17.5
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users.
network
low complexity
tangro CWE-732
4.0
2020-12-18 CVE-2020-26175 Incorrect Permission Assignment for Critical Resource vulnerability in Tangro Business Workflow 1.17.5
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.
network
low complexity
tangro CWE-732
4.0
2020-12-18 CVE-2020-26173 Improper Authentication vulnerability in Tangro Business Workflow 1.17.5
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token.
network
low complexity
tangro CWE-287
4.0
2020-12-18 CVE-2020-26171 Incorrect Permission Assignment for Critical Resource vulnerability in Tangro Business Workflow 1.17.5
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated.
network
low complexity
tangro CWE-732
4.0