go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Digiwin|EasyFlow .NET and EasyFlow AiNet - SQL Injection

TVN ID TVN-202511001
CVE ID CVE-2025-12503
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products EasyFlow .NET version 6.6.19 and earlier
EasyFlow AiNet version 8.1.1 and earlier
Description EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Solution Update EasyFlow.NET to version 6.6.19 and install the patch 20250520
Update EasyFlow AiNet to version 8.1.1 and install the patch 20250520
Credit Sam Huang(CHT Security)
Public Date 2025-11-03
Top