CyberRota Analysis
AI-GeneratedThe Flowring Agentflow 4.0 version prior to August 28, 2026, contains a vulnerability in the /WebAgenda/SQLWin.do API endpoint that allows remote authenticated users to execute arbitrary SQL commands through the sql parameter. This could lead to unauthorized data manipulation or exposure, posing a significant risk to the integrity and confidentiality of the database. Organizations using this version should prioritize patching to mitigate potential exploitation.
Original NVD Description
Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.