Post Date: 2026/05/13

【Vulnerability Alert】Digiwin Software|EasyFlow.NET - Two Vulnerabilities Identified

  • Subject: 【Vulnerability Alert】Digiwin Software|EasyFlow.NET - Two Vulnerabilities Identified


  • Description:
    • Forwarded from Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) Security Alert: TWCERTCC-200-202604-00000023
    • 【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5963, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
    • 【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5964, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
  • Affected Platforms:
    • EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2, V8.1.3, V8.1.4
    • EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2
  • Recommended Actions:
    • 【CVE-2026-5963】 Update to version v8.1.5 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
    • 【CVE-2026-5964】 Update to version v8.1.3 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
  • Reference Materials:

Computer and Communication Center
Network Systems Division