Back to all
2026-09-29

Flowring Agentflow 4.0 - SQL Injection

ZUSOART ID
ZA-2026-09
CVE ID
CVE-2026-96428
Vulnerability Type
CWE-89: Improper Neutralization of Special Elements used in an SQL Command('SQL Injection')
CVSS 4.0 Base
9.3
Description

SQL Injection in the  /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version  before 2025/08/08 allows remote attackers to execute arbitrary SQL commands  via the words parameter.

‍

Vendor
Flowring Technology Corp
Product
Category
Version affected
Agentflow 4.0
Before 2025/08/08
Mitigations

Update Agentflow 4.0 to 2025/08/08.

‍

Release date
2026-09-29
Credit

Kuang Ming Chang of ZUSO ART