CVE-2022-26514

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
29/03/2022
Last modified:
01/04/2022

Description

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* 1.8.02.004 (excluding)


References to Advisories, Solutions, and Tools