Sceawere

Vulnerability Detail

CVE-2026-102454UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

EasyFlow .NET Arbitrary File Upload

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
DigiWin
Product
EasyFlow .NET
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T09:17:13.170Z",
  "pubdate": "2026-09-30T09:17:13.170Z",
  "executiveSummary": "EasyFlow .NET, developed by Digiwin, is susceptible to an Arbitrary File Upload vulnerability.\nThis vulnerability allows a privileged remote attacker to bypass file validation mechanisms and upload malicious files directly to the web server.\nThe primary impact is the potential for Remote Code Execution (RCE) via the execution of uploaded web shell backdoors, granting the attacker full control over the application environment.\nThe vulnerability poses a critical risk to the confidentiality, integrity, and availability of the server and any data managed by the system.\nExploitation requires the attacker to possess authenticated, privileged access to the application’s administrative or file-handling interfaces.\nSuccessful exploitation facilitates unauthorized system commands, data exfiltration, and persistent access to the network infrastructure.",
  "technicalDetails": "The vulnerability originates from inadequate server-side validation of user-supplied files within the EasyFlow .NET application.\nSpecifically, the application fails to restrict the types of files that can be uploaded via its designated upload interfaces, allowing for the submission of executable scripts or binaries.\nThe attack flow commences with the attacker authenticated as a privileged user navigating to the vulnerable upload module within the Digiwin EasyFlow .NET interface.\nThe attacker sends a crafted HTTP POST request containing a malicious payload, typically a web shell (such as an .aspx file), disguised as an authorized document or image.\nBecause the server-side implementation lacks strict extension filtering or MIME-type verification, the malicious file is written to a web-accessible directory.\nOnce the file is successfully placed on the server, the attacker can trigger its execution by sending an HTTP request directly to the path where the file was stored (e.g., /uploads/shell.aspx).\nUpon execution by the .NET runtime, the web shell grants the attacker an interactive command shell with the permissions of the web service account (e.g., IIS_IUSRS).\nThis elevated context allows the attacker to interact with the underlying operating system, move laterally within the network, or deploy further post-exploitation payloads.\nThe lack of integrity checks on file metadata and the absence of restricted file-system permissions for upload directories contribute to the feasibility of this attack.\nThe persistence of the threat is maintained through the continued existence of the backdoored file on the server, even if the session used for the initial upload is terminated."
}
CVE-2026-102454: EasyFlow .NET Arbitrary File Upload (HIGH Severity, CVSS: 7.2) | Sceawere