Description
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
References
https://www.twcert.org.tw/tw/cp-132-7844-52dad-1.html