CVE-2026-102459: DigiWin|EasyFlow .NET - Reflected Cross-site Scripting
Published Sep 30, 2026
·Updated
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Affected Software
1 affected component
Digiwin EasyFlow .NET
Event History
Sep 30, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of Digiwin EasyFlow .NET are exposed if they can be persuaded to visit a crafted link or otherwise interact with phishing content. The attacker does not need to authenticate to target them.
2
What does an attacker need to exploit it?
An attacker needs network access and user interaction, such as convincing a user through phishing to open a malicious request. No attacker privileges or authentication are required.