Flowring

Agentflow

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 29.09.2026 09:17:11
  • Zuletzt bearbeitet 29.09.2026 21:33:56

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.

  • EPSS 0.28%
  • Veröffentlicht 29.09.2026 09:17:11
  • Zuletzt bearbeitet 29.09.2026 21:33:56

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.

  • EPSS 0.29%
  • Veröffentlicht 29.09.2026 09:17:11
  • Zuletzt bearbeitet 30.09.2026 16:19:26

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locat...

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 09:17:10
  • Zuletzt bearbeitet 29.09.2026 21:33:56

SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.

  • EPSS 0.28%
  • Veröffentlicht 29.09.2026 09:17:10
  • Zuletzt bearbeitet 29.09.2026 21:33:56

SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • EPSS 0.52%
  • Veröffentlicht 10.02.2026 07:16:14
  • Zuletzt bearbeitet 13.02.2026 20:52:16

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

  • EPSS 0.44%
  • Veröffentlicht 10.02.2026 07:16:14
  • Zuletzt bearbeitet 13.02.2026 20:51:42

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • EPSS 0.2%
  • Veröffentlicht 10.02.2026 07:16:14
  • Zuletzt bearbeitet 13.02.2026 20:49:31

AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • EPSS 0.17%
  • Veröffentlicht 10.02.2026 07:16:14
  • Zuletzt bearbeitet 13.02.2026 20:48:06

AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

  • EPSS 0.51%
  • Veröffentlicht 10.02.2026 07:16:13
  • Zuletzt bearbeitet 13.02.2026 20:53:19

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.