Executive brief
Digiwin EasyFlow .NET, an enterprise workflow management system, is vulnerable to a session fixation flaw. An attacker can pre-set a specific session identifier for a legitimate user; once that user logs in, the attacker can hijack their session to gain unauthorized access to the system. This could lead to the exposure of sensitive corporate data or unauthorized execution of business workflows.
Technical details
A session fixation vulnerability (CWE-384) exists in Digiwin EasyFlow .NET version 8.1.4 and earlier. The application fails to renew the session identifier upon a successful user login. An unauthenticated remote attacker can exploit this by forcing a known session ID onto a victim's browser (typically via link manipulation or other session injection techniques). If the victim subsequently authenticates using that fixed session ID, the attacker can use the same ID to impersonate the user and gain their full privileges. The vulnerability is addressed in version 8.1.5.
Affected products
- Digiwin EasyFlow .NET 8.1.4 and earlier
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory
- 2026-06-22: patched: Fixed in version 8.1.5