Executive brief
EasyFlow .NET, a business process management and workflow automation platform, contains a security flaw that allows logged-in users to plant malicious scripts within the application. When other users, such as administrators or colleagues, view the affected pages, these scripts execute automatically in their browsers. This could lead to the theft of sensitive session information, unauthorized actions performed on behalf of other users, or the defacement of internal workflow pages.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Digiwin EasyFlow .NET version 8.1.4 and earlier due to improper neutralization of user-provided input during web page generation (CWE-79). An authenticated remote attacker with low privileges can inject persistent JavaScript code into specific application pages. This code is subsequently executed in the security context of any user who views the compromised page. Successful exploitation requires minimal user interaction (viewing the page) and can result in the disclosure of session cookies or the performance of unauthorized actions in the victim's browser. The vulnerability is addressed in version 8.1.5.
Affected products
- Digiwin (鼎新數智) EasyFlow .NET 8.1.4 and earlier
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory
- 2026-06-22: patched: Fixed in version 8.1.5