Post Date: 2026/05/13
【Vulnerability Alert】Digiwin Software|EasyFlow.NET - Two Vulnerabilities Identified
- Subject: 【Vulnerability Alert】Digiwin Software|EasyFlow.NET - Two Vulnerabilities Identified
- Description:
- Forwarded from Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) Security Alert: TWCERTCC-200-202604-00000023
- 【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5963, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
- 【Digiwin Software|EasyFlow.NET - SQL Injection】(CVE-2026-5964, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.
- Affected Platforms:
- EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2, V8.1.3, V8.1.4
- EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2
- Recommended Actions:
- 【CVE-2026-5963】 Update to version v8.1.5 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
- 【CVE-2026-5964】 Update to version v8.1.3 (inclusive) or later, or apply the Patch updated as of 2026/01/20.
- Reference Materials:
Computer and Communication Center
Network Systems Division