CVE-2026-102456: DigiWin|EasyFlow - SQL Injection
Published Sep 30, 2026
·Updated
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
Affected Software
1 affected component
Digiwin EasyFlow .NET
Event History
Sep 30, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated remote attacker can exploit it. The supplied data does not identify any affected versions, deployment conditions, or whether default credentials or configurations increase exposure.
2
What could an attacker obtain through successful exploitation?
The attacker can inject arbitrary SQL commands and read database contents. The available information does not state that the issue permits data modification, deletion, or service disruption.