Filtered by vendor Digiwin Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-32457 1 Digiwin 1 Business Process Management 2024-09-16 5.3 Medium
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
CVE-2022-32458 1 Digiwin 1 Business Process Management 2024-09-16 7.5 High
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
CVE-2022-32456 1 Digiwin 1 Business Process Management 2024-09-16 9.8 Critical
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
CVE-2024-7323 1 Digiwin 1 Easyflow .net 2024-09-11 6.5 Medium
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .