Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-7323

Disclosure Date: August 02, 2024 (last updated September 12, 2024)
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
Attacker Value
Unknown

CVE-2024-5311

Disclosure Date: June 03, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
0
Attacker Value
Unknown

CVE-2024-4893

Disclosure Date: May 15, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
0
Attacker Value
Unknown

CVE-2022-32458

Disclosure Date: July 11, 2022 (last updated December 22, 2024)
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
Attacker Value
Unknown

CVE-2022-32457

Disclosure Date: July 11, 2022 (last updated December 22, 2024)
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Attacker Value
Unknown

CVE-2022-32456

Disclosure Date: July 11, 2022 (last updated December 22, 2024)
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.