Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
Tangro Business Workflow 授权问题漏洞
Vulnerability Description
Tangro Business Workflow是德国Tangro公司的一款可将SAP文档内容的内部控制以及批准流程进行可视化绘制的软件。 tangro Business Workflow before 1.18.1 存在安全漏洞,攻击者可利用该漏洞可以操作api配置文件请求中的PERSON值,从而更改其他用户的配置文件信息。
CVSS Information
N/A
Vulnerability Type
N/A