Client-side file type restriction bypass in tangro Business Workflow before 1.18.1

Client-side file type restriction bypass in tangro Business Workflow before 1.18.1

CVE-2020-26174 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a workitem.

Learn more about our Cis Benchmark Audit For Server Software.