Medium severity6.5NVD Advisory· Published Aug 2, 2024· Updated Jun 17, 2026
CVE-2024-7323
CVE-2024-7323
Description
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 2 more
- (no CPE)
- (no CPE)range: 5.*
- cpe:2.3:a:digiwin:easyflow_.net:*:*:*:*:*:*:*:*range: <6.6.17
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/en/cp-139-7990-87183-2.htmlnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-7989-9c4ea-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.