EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digiwin
Digiwin easyflow .net |
|
| Vendors & Products |
Digiwin
Digiwin easyflow .net |
Mon, 03 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Title | Digiwin|EasyFlow .NET and EasyFlow AiNet | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-11-03T06:51:55.994Z
Updated: 2025-11-03T13:48:19.281Z
Reserved: 2025-10-30T12:15:03.063Z
Link: CVE-2025-12503
Updated: 2025-11-03T13:48:16.044Z
Status : Awaiting Analysis
Published: 2025-11-03T07:15:41.480
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-12503
No data.