EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in. | |
| Title | Digiwin|EasyFlow .NET - Session Fixation | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-06-22T10:26:23.605Z
Reserved: 2026-06-18T06:51:13.798Z
Link: CVE-2026-12581
Updated: 2026-06-22T10:26:18.313Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T12:00:05Z