Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Digiwin
Digiwin easyflow .net |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:digiwin:easyflow_.net:*:*:*:*:*:*:*:* | |
Vendors & Products |
Digiwin
Digiwin easyflow .net |
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-08-02T10:36:51.855Z
Updated: 2024-08-02T14:02:20.958Z
Reserved: 2024-07-31T11:18:44.196Z
Link: CVE-2024-7323
Vulnrichment
Updated: 2024-08-02T14:02:16.440Z
NVD
Status : Analyzed
Published: 2024-08-02T11:16:44.220
Modified: 2024-09-11T14:22:46.903
Link: CVE-2024-7323
Redhat
No data.