CVE-2022-43774: SQL Injection
Published Oct 26, 2022
·Updated
The HandlerPagePKID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
Affected Software
1 affected component
Deltaww Diaenergie=1.9.0
Event History
Oct 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2022-43774.
2
What is the affected software and version?
The affected software is Delta Electronics DIAEnergy v1.9.
3
What is the severity of CVE-2022-43774?
The severity of CVE-2022-43774 is critical with a CVSS score of 9.8.
4
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-89.
5
Is there a fix available for CVE-2022-43774?
Yes, it is recommended to update to a fixed version provided by the software vendor.