SQL Injection Vulnerability in EasyFlow Products by Digiwin
CVE-2025-12503
7.1HIGH
What is CVE-2025-12503?
EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, are impacted by a SQL Injection vulnerability. This flaw allows authenticated remote attackers to execute arbitrary SQL commands, potentially enabling them to read sensitive database contents. As a result, organizations utilizing these products should prioritize securing their database access to mitigate potential data breaches.
Affected Version(s)
EasyFlow .NET 0 <= 6.6.19
EasyFlow AiNet 0 <= 8.1.1
