Description
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
No analysis available yet.
Remediation
Vendor Solution
Install patch for V5.x and V6.1.x (released on 2024/02/01 or later). Update V6.6.x to V6.6.16 or later version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46545 | DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7844-52dad-1.html |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:11:12.377Z
Reserved: 2024-05-24T07:09:03.399Z
Link: CVE-2024-5311
Updated: 2024-08-01T21:11:12.377Z
Status : Deferred
Published: 2024-06-03T07:15:10.163
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5311
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:23Z
Weaknesses
EUVD