tangro kayıtları
tangro üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-306 Missing Authentication for Critical Function1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-669 Incorrect Resource Transfer Between Spheres1
- CWE-922 Insecure Storage of Sensitive Information1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-26174İstismar yok | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes containedtangro · business workflow · CWE-434 | Yüksek8,8 | — | %1,2 | 18 Ara 2020 |
26İzleyin | CVE-2020-26175İstismar yok | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change protangro · business workflow · CWE-639 | Orta6,5 | — | %0,7 | 18 Ara 2020 |
26İzleyin | CVE-2020-26172İstismar yok | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a sessitangro · business workflow · CWE-294 | Orta6,5 | — | %0,7 | 18 Ara 2020 |
21İzleyin | CVE-2020-26178İstismar yok | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authentictangro · business workflow · CWE-639 | Orta5,3 | — | %0,9 | 18 Ara 2020 |
17İzleyin | CVE-2020-26176İstismar yok | An issue was discovered in tangro Business Workflow before 1.18.1.tangro · business workflow · CWE-922 | Orta4,3 | — | %0,8 | 18 Ara 2020 |
17İzleyin | CVE-2020-26173İstismar yok | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by provitangro · business workflow · CWE-306 | Orta4,3 | — | %0,7 | 18 Ara 2020 |
17İzleyin | CVE-2020-26177İstismar yok | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited btangro · business workflow · CWE-669 | Orta4,3 | — | %0,6 | 18 Ara 2020 |
17İzleyin | CVE-2020-26171İstismar yok | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated.tangro · business workflow · CWE-639 | Orta4,3 | — | %0,6 | 18 Ara 2020 |
- CVE-2020-2617435İzleyin
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained
YüksekCVSS 8,8İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617526İzleyin
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change pro
OrtaCVSS 6,5İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617226İzleyin
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a sessi
OrtaCVSS 6,5İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617821İzleyin
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authentic
OrtaCVSS 5,3İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617617İzleyin
An issue was discovered in tangro Business Workflow before 1.18.1.
OrtaCVSS 4,3İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617317İzleyin
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by provi
OrtaCVSS 4,3İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617717İzleyin
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited b
OrtaCVSS 4,3İstismar yokEPSS %1tangro · business workflow18 Ara 2020
- CVE-2020-2617117İzleyin
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated.
OrtaCVSS 4,3İstismar yokEPSS %1tangro · business workflow18 Ara 2020