Impact
Agentflow developed by Flowring has a Missing Authentication vulnerability that allows unauthenticated remote attackers to read, modify, and delete database contents by invoking a specific functionality. The flaw permits attackers to compromise confidentiality through data read, and integrity by altering or erasing data.
Affected Systems
The affected product is Flowring Agentflow. No specific version information is provided in the data, so the scope of affected releases is currently unknown.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical exposure, yet the EPSS score of less than 1% suggests that exploitation may be rare at present. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploitation. Based on the description, the likely attack vector is remote over the network via an exposed Agentflow endpoint; authenticated controls are missing, allowing any network‐connected adversary to execute the vulnerable functionality.
OpenCVE Enrichment