← back
CVE-2020-26173

CVE-2020-26173

CVSS 3.1 LOWEPSS 0.7%
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →