CVE-2024-7323: Digiwin Easyflow .net
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
Affected products
- Digiwin Easyflow .net: before 6.6.17 (fixed in 6.6.17)
Published 2024-08-02. Last modified 2026-06-17.