6.1
CVE-2026-102459
- EPSS 0.2%
- Veröffentlicht 30.09.2026 08:35:41
- Zuletzt bearbeitet 30.09.2026 16:30:42
- Erkennungen
DigiWin|EasyFlow .NET - Reflected Cross-site Scripting
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDigiWin
≫
Produkt
EasyFlow .NET
Default Statusunaffected
Version
6.1.x
Status
affected
Version <=
6.6.19
Version
6.6
Status
affected
Version <=
8.1.5
Version
8.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.09 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cert TW | 5.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| Cert TW | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html
https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html