CVE detail
CVE-2020-26177 — CVE-2020-26177
Published 2020-12-18 · Modified 2026-06-17 · Vendor tangro · Product business_workflow · Source nvd
MEDIUM
severity
CVSS-derived band
0.0064
EPSS probability
exploitation probability, 30d
48.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the greyed-out values in requests to /api/profile is not prohibited server-side.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References