Sceawere
Vulnerability Detail
CVE-2026-102456UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
EasyFlow .NET SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- DigiWin
- Product
- EasyFlow .NET
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T09:17:13.503Z",
"pubdate": "2026-09-30T09:17:13.503Z",
"executiveSummary": "The EasyFlow .NET platform, developed by Digiwin, is susceptible to a critical SQL Injection (SQLi) vulnerability.\nThis flaw resides within the application's data processing layers, allowing authenticated remote attackers to manipulate backend database queries.\nBy injecting arbitrary SQL commands, unauthorized actors can bypass application logic to extract sensitive database contents, compromise data integrity, or potentially gain further control over the underlying database management system.\nThe vulnerability poses a severe risk to organizational confidentiality and data security, as it facilitates unauthorized access to backend information stores.\nSuccessful exploitation requires the attacker to possess valid user credentials to access the application environment, after which they can leverage the injection vector to execute malicious queries.\nGiven the nature of SQL Injection, the impact is significant, potentially leading to full database exposure or unauthorized administrative access to application data.",
"technicalDetails": "The vulnerability manifests as an improper neutralization of special elements used in an SQL command during the processing of user-supplied input. In EasyFlow .NET, the application fails to adequately sanitize or parameterize input parameters before incorporating them into dynamic SQL query strings.\nThe root cause is identified as the application's reliance on unsanitized user input within database query construction. When an authenticated user submits input to a vulnerable endpoint, the application concatenates this data directly into the SQL command without employing parameterized queries or prepared statements.\nThe attack flow commences when an authenticated attacker identifies an input field or parameter that is improperly processed by the application's backend. By injecting malicious SQL syntax—such as union-based or error-based payloads—the attacker can alter the intended logic of the database query. Because the application processes these requests in the context of an authenticated session, the database engine executes the injected commands with the privileges assigned to the database service account.\nExploitation allows the attacker to manipulate the execution flow of the database engine, enabling the retrieval of unintended data sets, enumeration of database schemas, or dumping of tables containing sensitive business or user information. If the database service account possesses excessive permissions, the impact could extend to modifying data, dropping tables, or performing unauthorized administrative operations.\nThe vulnerability is restricted to authenticated remote actors, meaning the attacker must possess valid credentials to access the vulnerable functionality. However, once authenticated, the attacker can interact with the vulnerable component over the network to send crafted payloads. The lack of robust input validation and the use of dynamic string concatenation in the backend component remain the primary technical drivers for this security flaw."
}