Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.
The vulnerability results from the lack of an authentication mechanism in a specific functionality of the Agentflow system. An attacker can remotely invoke this functionality over the network without possessing any credentials. This results in full access to database operations — reading, modifying, and deleting records.
An attacker can read sensitive data stored in the database without authentication, as well as modify or permanently delete it, which may lead to violation of data integrity and confidentiality as well as disruption of system operation.
Apply patches available from the manufacturer in accordance with references (forum.flowring.com and TWCERT/CC)
Flowring Agentflow — versions indicated in manufacturer references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFlowring Agentflow
APPFlowringall versions
Related vulnerabilities
Pomijanie uwierzytelnienia w Flowring Agentflow — przejęcie tokenu dowolnego użytkownika
Flowring Agentflow — pominięcie blokady konta umożliwia atak brute force
Flowring Agentflow BPM — nieuwierzytelniony upload pliku i RCE
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote atta...
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user pr...