Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.
| Software | From | Fixed in |
|---|---|---|
| flowring / agentflow | 4.0.0.1183.552 | 4.0.0.1183.552.x |