CVE-2022-1366: SQL Injection
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
This vulnerability is identified by the ID CVE-2022-1366.
What is the affected software?
The affected software is Delta Electronics DIAEnergie versions prior to 1.8.02.004.
What is the severity of CVE-2022-1366?
The severity of this vulnerability is critical with a CVSS score of 9.8.
What is the vulnerability description?
CVE-2022-1366 is a blind SQL injection vulnerability in Delta Electronics DIAEnergie, allowing attackers to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Is there a fix available for CVE-2022-1366?
Yes, updating Delta Electronics DIAEnergie to version 1.8.02.004 or later will fix this vulnerability.