← Back to CVE List

CVE-2020-26176

Published: 2020-12-18T10:15Z
Last Modified: 2024-11-21T05:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt