CVE-2026-102459

Summary

EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.

Affected Software

VendorProductVersion RangeStatus
DigiWinEasyFlow .NET6.1.xaffected
DigiWinEasyFlow .NET6.6 <= 6.6.19affected
DigiWinEasyFlow .NET8.1 <= 8.1.5affected

Weaknesses

  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References