Записи tangro
8 опубликованных записей вендора tangro.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-306 Missing Authentication for Critical Function1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-669 Incorrect Resource Transfer Between Spheres1
- CWE-922 Insecure Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-26174Эксплойта нет | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes containedtangro · business workflow · CWE-434 | Высокая8,8 | — | 1,2 % | 18 дек. 2020 г. |
26Наблюдать | CVE-2020-26175Эксплойта нет | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change protangro · business workflow · CWE-639 | Средняя6,5 | — | 0,7 % | 18 дек. 2020 г. |
26Наблюдать | CVE-2020-26172Эксплойта нет | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a sessitangro · business workflow · CWE-294 | Средняя6,5 | — | 0,7 % | 18 дек. 2020 г. |
21Наблюдать | CVE-2020-26178Эксплойта нет | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authentictangro · business workflow · CWE-639 | Средняя5,3 | — | 0,9 % | 18 дек. 2020 г. |
17Наблюдать | CVE-2020-26176Эксплойта нет | An issue was discovered in tangro Business Workflow before 1.18.1.tangro · business workflow · CWE-922 | Средняя4,3 | — | 0,8 % | 18 дек. 2020 г. |
17Наблюдать | CVE-2020-26173Эксплойта нет | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by provitangro · business workflow · CWE-306 | Средняя4,3 | — | 0,7 % | 18 дек. 2020 г. |
17Наблюдать | CVE-2020-26177Эксплойта нет | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited btangro · business workflow · CWE-669 | Средняя4,3 | — | 0,6 % | 18 дек. 2020 г. |
17Наблюдать | CVE-2020-26171Эксплойта нет | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated.tangro · business workflow · CWE-639 | Средняя4,3 | — | 0,6 % | 18 дек. 2020 г. |
- CVE-2020-2617435Наблюдать
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617526Наблюдать
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change pro
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617226Наблюдать
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a sessi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617821Наблюдать
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authentic
СредняяCVSS 5,3Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617617Наблюдать
An issue was discovered in tangro Business Workflow before 1.18.1.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617317Наблюдать
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by provi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617717Наблюдать
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited b
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.
- CVE-2020-2617117Наблюдать
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tangro · business workflow18 дек. 2020 г.