Impact
EasyFlow .NET, a workflow automation product from DigiWin, contains an arbitrary file read flaw. Authenticated remote attackers can exploit the vulnerability to download any system files the application process can access, exposing sensitive data or configuration information.
Affected Systems
The vulnerability affects DigiWin:EasyFlow .NET. Affected product versions are not listed in the available data, so all released versions prior to the patch should be considered at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact when exploited. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. Attackers must have valid credentials and remote access to perform the exploit. Once authenticated, they can read arbitrary files, potentially leading to confidentiality loss and further pivoting within the system.
OpenCVE Enrichment