CVE-2026-12580: Digiwin|EasyFlow .NET - Stored Cross-Site Scripting
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Digiwin|EasyFlow .NETto a version that resolves this vulnerability.Fixed in 8.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12580?
CVE-2026-12580 has a medium severity rating of 5.4.
How do I fix CVE-2026-12580?
To fix CVE-2026-12580, ensure that proper input validation and output encoding are implemented to prevent Stored Cross-Site Scripting.
Who is affected by CVE-2026-12580?
CVE-2026-12580 affects users of Digiwin's EasyFlow .NET software who have authenticated access.
What type of vulnerability is CVE-2026-12580?
CVE-2026-12580 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2026-12580 result in data theft?
Yes, CVE-2026-12580 can lead to data theft as attackers may inject JavaScript to capture sensitive information from users.