CVE-2024-5311
EUVD-2024-4654503.06.2024, 07:15
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| digiwin | easyflow_.net | 6.6.x ≤ 𝑥 < 6.6.16 | ADP |