CVE-2020-26173
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
LOW · CVSS 3.1
EPSS 0.00147
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0