Description
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting that allows arbitrary JavaScript execution in users’ browsers
Action: Patch
AI Analysis

Impact

EasyFlow .NET contains a reflected cross‑site scripting flaw that permits an unauthenticated remote attacker to execute arbitrary JavaScript in the victim’s browser. The vulnerability is triggered when untrusted input is returned in a page without proper escaping, and it can be activated through phishing campaigns that embed malicious URLs. This flaw enables client‑side compromise of the user’s session and potentially the theft of sensitive data.

Affected Systems

The affected product is DigiWin EasyFlow .NET. No specific version numbers are disclosed in the advisory, but the patch is released after June 26, 2026.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, so the current exploitation probability is uncertain. The vulnerability is reachable remotely via phishing emails that deliver a crafted URL, allowing unauthenticated attackers to exploit the reflected XSS vector. Installing the patched version mitigates the risk.

Generated by OpenCVE AI on September 30, 2026 at 12:18 UTC.

Remediation

Vendor Solution

Update to the patch version released after June 26, 2026.


OpenCVE Recommended Actions

  • Apply the EasyFlow .NET patch released after June 26, 2026
  • Ensure that all untrusted input is properly sanitized and encoded before rendering in responses
  • Configure the web application to send protective HTTP headers such as Content‑Security‑Policy, X‑Content‑Type‑Options, and X‑XSS‑Protection to reduce the impact of any remaining XSS vectors

Generated by OpenCVE AI on September 30, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Digiwin
Digiwin easyflow .net
Vendors & Products Digiwin
Digiwin easyflow .net

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Title DigiWin|EasyFlow .NET - Reflected Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Digiwin Easyflow .net
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-30T08:35:41.463Z

Reserved: 2026-09-29T08:18:22.813Z

Link: CVE-2026-102459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:13.953

Modified: 2026-09-30T09:17:13.953

Link: CVE-2026-102459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')