Description
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Apply Patch
AI Analysis

Impact

EasyFlow .NET, developed by DigiWin, contains a SQL Injection flaw (CWE‑89) that allows an attacker who can authenticate remotely to inject arbitrary SQL commands. This capability enables the attacker to read sensitive database data, compromising the confidentiality of information stored in the application.

Affected Systems

The vulnerability applies to DigiWin EasyFlow .NET. No specific version information is provided, so all deployed instances of the product are potentially affected unless they have been updated beyond the patch released after June 26, 2026.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity vulnerability. The unknown EPSS score means we cannot assess current exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to the system, then issue malicious queries, suggesting that restricting database permissions and employing secure coding practices can mitigate the risk.

Generated by OpenCVE AI on September 30, 2026 at 11:20 UTC.

Remediation

Vendor Solution

Update to the patch version released after June 26, 2026.


OpenCVE Recommended Actions

  • Update EasyFlow .NET to the patch version released after June 26, 2026.
  • Reduce database privileges for the application user to the minimum required for normal operation to limit the damage of any injected SQL commands.
  • Review the application code for input validation, ensuring that all user-supplied data used in SQL statements is properly sanitized or passed through parameterized queries to eliminate injection paths.

Generated by OpenCVE AI on September 30, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Digiwin
Digiwin easyflow .net
Vendors & Products Digiwin
Digiwin easyflow .net

Wed, 30 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title DigiWin|EasyFlow - SQL Injection DigiWin|EasyFlow .NET - SQL Injection

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
Title DigiWin|EasyFlow - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digiwin Easyflow .net
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-30T15:28:09.246Z

Reserved: 2026-09-29T08:18:19.347Z

Link: CVE-2026-102456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T09:17:13.503

Modified: 2026-09-30T16:30:42.327

Link: CVE-2026-102456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')