CVE-2022-1367: SQL Injection
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1367.
What is the severity of CVE-2022-1367?
The severity of CVE-2022-1367 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software is Delta Electronics DIAEnergie, all versions prior to 1.8.02.004.
What is the description of CVE-2022-1367?
CVE-2022-1367 is a blind SQL injection vulnerability that exists in Handler_TCV.ashx of Delta Electronics DIAEnergie, allowing attackers to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Is there a fix available for CVE-2022-1367?
Yes, updating to version 1.8.02.004 or later of Delta Electronics DIAEnergie resolves the vulnerability.