CVE-2025-13163
MEDIUMEasyFlow GP - Info Disclosure
Title source: llmDescription
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend.
Scores
CVSS v3
4.9
EPSS
0.0005
EPSS Percentile
16.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
draft
Timeline
Published
Nov 17, 2025
Tracked Since
Feb 18, 2026