CVE-2026-102456

Summary

EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.

Affected Software

VendorProductVersion RangeStatus
DigiWinEasyFlow .NET6.1.*affected
DigiWinEasyFlow .NET6.6 <= 6.6.19affected
DigiWinEasyFlow .NET8.1 <= 8.1.5affected

Weaknesses

  • CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References