EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digiwin:easyflow_.net:*:*:*:*:*:*:*:* |
Tue, 12 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digiwin:easyflow_.net:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:digiwin:easyflow_.net:6.6.0:*:*:*:*:*:*:* cpe:2.3:a:digiwin:easyflow_.net:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:digiwin:easyflow_.net:8.1.2:*:*:*:*:*:*:* |
Mon, 20 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digiwin
Digiwin easyflow .net |
|
| Vendors & Products |
Digiwin
Digiwin easyflow .net |
Mon, 20 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Title | Digiwin|EasyFlow .NET - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2026-04-20T07:36:58.476Z
Updated: 2026-04-20T13:38:08.600Z
Reserved: 2026-04-09T10:34:41.136Z
Link: CVE-2026-5964
Updated: 2026-04-20T13:38:04.893Z
Status : Analyzed
Published: 2026-04-20T08:16:10.850
Modified: 2026-05-12T16:14:12.893
Link: CVE-2026-5964
No data.