Known Vulnerabilities for products from Tangro
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Tangro".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-26178 json | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without ... | 5.3 - MEDIUM | 2020-12-18 | 2020-12-21 |
| CVE-2020-26177 json | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended... | 4.3 - MEDIUM | 2020-12-18 | 2021-07-21 |
| CVE-2020-26176 json | An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/doc... | 4.3 - MEDIUM | 2020-12-18 | 2020-12-21 |
| CVE-2020-26175 json | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in orde... | 6.5 - MEDIUM | 2020-12-18 | 2021-07-21 |
| CVE-2020-26174 json | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the file... | 8.8 - HIGH | 2020-12-18 | 2020-12-21 |
| CVE-2020-26173 json | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents... | 4.3 - MEDIUM | 2020-12-18 | 2021-07-21 |
| CVE-2020-26172 json | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the tok... | 6.5 - MEDIUM | 2020-12-18 | 2020-12-21 |
| CVE-2020-26171 json | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be ma... | 4.3 - MEDIUM | 2020-12-18 | 2021-07-21 |
Known software with vulnerabilities from Tangro
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Tangro | Business Workflow | 1.17.5 |