Description
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
No analysis available yet.
Remediation
Vendor Solution
Install patch for V3.x, V5.x and V6.1.x (released on 2023/12/30 or later). Update V6.6.x to V6.6.15 or later version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44461 | DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T20:55:10.269Z
Reserved: 2024-05-15T02:08:20.026Z
Link: CVE-2024-4893
Updated: 2024-08-01T20:55:10.269Z
Status : Deferred
Published: 2024-05-15T03:15:14.493
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-4893
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:24:00Z
Weaknesses
EUVD