go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

FLOWRING Agentflow BPM - Path Traversal

TVN ID TVN-202210011
CVE ID CVE-2022-39037
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products FLOWRING Agentflow BPM V.4.0.0.1183.552
Description Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Solution Contact tech support from FLOWRING
Credit Alan Chung、Kaibro (DEVCORE)
Public Date 2022-11-10
Top