CVE-2022-26338: Delta Electronics DIAEnergie SQL Injection in DIAE_hierarchyHandler.ashx
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPagePKID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-26338.
What is the severity rating of CVE-2022-26338?
The severity rating of CVE-2022-26338 is critical with a value of 9.8.
What software versions are affected by CVE-2022-26338?
All versions prior to 1.8.02.004 of Delta Electronics DIAEnergie are affected by CVE-2022-26338.
What is the description of CVE-2022-26338?
CVE-2022-26338 is a blind SQL injection vulnerability in Delta Electronics DIAEnergie (All versions prior to 1.8.02.004), specifically in HandlerPageP_KID.ashx, allowing an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
How can I fix CVE-2022-26338?
To fix CVE-2022-26338, it is recommended to update Delta Electronics DIAEnergie to version 1.8.02.004 or later.