DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-05-15T02:31:29.475Z

Updated: 2024-08-01T20:55:10.269Z

Reserved: 2024-05-15T02:08:20.026Z

Link: CVE-2024-4893

cve-icon Vulnrichment

Updated: 2024-08-01T20:55:10.269Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T03:15:14.493

Modified: 2024-05-15T16:40:19.330

Link: CVE-2024-4893

cve-icon Redhat

No data.