FLOWRING Agentflow BPM - Broken Access Control
CVE-2022-39038
8.8HIGH
What is CVE-2022-39038?
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.
Affected Version(s)
Agentflow BPM 4.0.0.1183.552
