Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
An attacker without any prior authentication can exploit a specific functionality of the Agentflow system, which improperly verifies the identity of the requester. Exploitation of this functionality allows obtaining an authentication token assigned to a selected user account. With such a token, the attacker can log into the system with full permissions of that user, including potentially an administrative account.
An attacker can gain unauthorized access to the Agentflow system as any user, including an administrator, which can lead to complete system takeover, disclosure of sensitive data, and compromise of the integrity of processed information.
Patches available from the vendor should be applied according to the references (forum.flowring.com and TWCERT/CC)
Flowring Agentflow — versions indicated in the vendor's references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFlowring Agentflow
APPFlowringall versions
Related vulnerabilities
Flowring Agentflow — brak uwierzytelnienia umożliwia manipulację bazą danych
Flowring Agentflow — pominięcie blokady konta umożliwia atak brute force
Flowring Agentflow BPM — nieuwierzytelniony upload pliku i RCE
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote atta...
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user pr...