CVE-2025-13164: Digiwin Easyflow Gp
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend.
Affected products
- Digiwin Easyflow Gp: from 5.8.8.3, up to and including 5.8.11.1.0810112
Published 2025-11-17. Last modified 2026-10-07.