Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update EasyFlow.NET to version 6.6.19 and install the patch 20250520 Update EasyFlow AiNet to version 8.1.1 and install the patch 20250520
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Title | Digiwin|EasyFlow .NET and EasyFlow AiNet | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-11-03T13:48:19.281Z
Reserved: 2025-10-30T12:15:03.063Z
Link: CVE-2025-12503
Updated: 2025-11-03T13:48:16.044Z
Status : Received
Published: 2025-11-03T07:15:41.480
Modified: 2025-11-03T07:15:41.480
Link: CVE-2025-12503
No data.
OpenCVE Enrichment
No data.