Description:
Forwarded from Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) Security Alert: TWCERTCC-200-202604-00000023
【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5963, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5964, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
Affected Platforms:
EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2, V8.1.3, V8.1.4
EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2
Recommended Actions:
【CVE-2026-5963】 Update to version v8.1.5 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
【CVE-2026-5964】 Update to version v8.1.3 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
Reference Materials:
-
Computer and Communication Center
Network Systems Division