CVE 6.9 MEDIUM

Digiwin|EasyFlow GP – Insufficiently Protected Credentials_CVE-2025-13164

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend.

Basic Information

ID CVE-2025-13164
Source twcert
Published Nov 17, 2025 at 06:23

Affected Product

Vendor Digiwin
Product EasyFlow GP
Version 5.8.8.3
Affected Versions Digiwin EasyFlow GP 5.8.8.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.