CVE-2026-78311: SQL Injection in DIAEnergie
SQL Injection vulnerability in DIAEnergie.
This issue affects DIAEnergie: before 1.11.00.022.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DIAEnergieto a version that resolves this vulnerability.Fixed in 1.11.00.022
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. This means an attacker would need some authenticated access with limited permissions to reach the vulnerable functionality.
Which DIAEnergie versions are affected?
DIAEnergie versions before 1.11.00.022 are affected. Upgrading to 1.11.00.022 or later addresses the affected version range.
What is the potential impact if exploitation succeeds?
The reported CVSS impacts indicate high potential impact to confidentiality, integrity, and availability. Successful SQL injection could therefore expose or alter data and disrupt the affected application.