Impact
EasyFlow .NET, developed by DigiWin, contains a SQL Injection flaw (CWE‑89) that allows an attacker who can authenticate remotely to inject arbitrary SQL commands. This capability enables the attacker to read sensitive database data, compromising the confidentiality of information stored in the application.
Affected Systems
The vulnerability applies to DigiWin EasyFlow .NET. No specific version information is provided, so all deployed instances of the product are potentially affected unless they have been updated beyond the patch released after June 26, 2026.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity vulnerability. The unknown EPSS score means we cannot assess current exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to the system, then issue malicious queries, suggesting that restricting database permissions and employing secure coding practices can mitigate the risk.
OpenCVE Enrichment