Description
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10699-49c0b-1.html
www.twcert.org.tw/en/cp-139-10700-3534d-2.html
forum.flowring.com/...view?bid=72&id=45611&tpg=1&ppg=1&sty=1