DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-44461 DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
Fixes

Solution

Install patch for V3.x, V5.x and V6.1.x (released on 2023/12/30 or later). Update V6.6.x to V6.6.15 or later version.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T20:55:10.269Z

Reserved: 2024-05-15T02:08:20.026Z

Link: CVE-2024-4893

cve-icon Vulnrichment

Updated: 2024-08-01T20:55:10.269Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T03:15:14.493

Modified: 2024-11-21T09:43:48.507

Link: CVE-2024-4893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:24:00Z