Impact
EasyFlow .NET contains a reflected cross‑site scripting flaw that permits an unauthenticated remote attacker to execute arbitrary JavaScript in the victim’s browser. The vulnerability is triggered when untrusted input is returned in a page without proper escaping, and it can be activated through phishing campaigns that embed malicious URLs. This flaw enables client‑side compromise of the user’s session and potentially the theft of sensitive data.
Affected Systems
The affected product is DigiWin EasyFlow .NET. No specific version numbers are disclosed in the advisory, but the patch is released after June 26, 2026.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, so the current exploitation probability is uncertain. The vulnerability is reachable remotely via phishing emails that deliver a crafted URL, allowing unauthenticated attackers to exploit the reflected XSS vector. Installing the patched version mitigates the risk.
OpenCVE Enrichment