CVE-2022-26836: Delta Electronics DIAEnergie SQL Injection in HandlerExport.ashx/Calendar.ashx
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for the Delta Electronics DIAEnergie blind SQL injection vulnerability?
The vulnerability ID for the Delta Electronics DIAEnergie blind SQL injection vulnerability is CVE-2022-26836.
What is the severity of CVE-2022-26836?
The severity of CVE-2022-26836 is critical (9.8).
How does the blind SQL injection vulnerability in HandlerExport.ashx/Calendar affect Delta Electronics DIAEnergie?
The blind SQL injection vulnerability in HandlerExport.ashx/Calendar allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands in Delta Electronics DIAEnergie versions prior to 1.8.02.004.
Which software versions are affected by the Delta Electronics DIAEnergie blind SQL injection vulnerability?
All versions prior to 1.8.02.004 of Delta Electronics DIAEnergie are affected by the blind SQL injection vulnerability.
Is there a fix available for the Delta Electronics DIAEnergie blind SQL injection vulnerability?
Yes, upgrading to version 1.8.02.004 of Delta Electronics DIAEnergie will fix the blind SQL injection vulnerability.