DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46545 | DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records. |
Fixes
Solution
Install patch for V5.x and V6.1.x (released on 2024/02/01 or later). Update V6.6.x to V6.6.16 or later version.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7844-52dad-1.html |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:11:12.377Z
Reserved: 2024-05-24T07:09:03.399Z
Link: CVE-2024-5311
Updated: 2024-08-01T21:11:12.377Z
Status : Awaiting Analysis
Published: 2024-06-03T07:15:10.163
Modified: 2024-11-21T09:47:24.407
Link: CVE-2024-5311
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:23Z
Weaknesses
EUVD