Back to all
2026-09-29

Flowring Agentflow 4.0 - SQL Injection

ZUSOART ID
ZA-2026-10
CVE ID
CVE-2026-96429
Vulnerability Type
CWE-89: Improper Neutralization of Special Elements used in an SQL Command('SQL Injection')
CVSS 4.0 Base
9.3
Description

SQL  Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring  Agentflow 4.0 version before 2025/08/08 allows  remote attackers to execute arbitrary SQL commands via the id parameter.

‍

Vendor
Flowring Technology Corp
Product
Category
Version affected
Agentflow 4.0
Before 2025/08/08
Mitigations

Update Agentflow 4.0 to 2025/08/08.

‍

Release date
2026-09-29
Credit

Kuang Ming Chang of ZUSO ART