SQL Injection Vulnerability in EasyFlow .NET by Digiwin
CVE-2026-5964
9.3CRITICAL
What is CVE-2026-5964?
EasyFlow .NET, developed by Digiwin, contains a SQL Injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands. This security flaw can lead to unauthorized reading, modification, and deletion of database contents, potentially exposing sensitive information and compromising the integrity of the database.
Affected Version(s)
EasyFlow .NET 6.1.*
EasyFlow .NET 6.6.*
EasyFlow .NET 8.1.1 <= 8.1.2
