An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
Metrics
CVSS Version: 3.1 |
Base Score: 3.1 LOW Vector: CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N