CVE-2025-12503: Digiwin|EasyFlow .NET and EasyFlow AiNet
EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12503?
CVE-2025-12503 is classified as a high severity vulnerability due to its ability to allow authenticated remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2025-12503?
To fix CVE-2025-12503, you should update to the latest version of Digiwin EasyFlow .NET or Digiwin EasyFlow AiNet where the vulnerability has been addressed.
What type of vulnerability is CVE-2025-12503?
CVE-2025-12503 is a SQL Injection vulnerability which allows attackers to manipulate SQL queries executed by the application.
Who is affected by CVE-2025-12503?
CVE-2025-12503 affects users of Digiwin EasyFlow .NET and Digiwin EasyFlow AiNet applications.
Can CVE-2025-12503 lead to data exposure?
Yes, CVE-2025-12503 can lead to data exposure as it allows attackers to read sensitive database contents through SQL injection.