"value":"\nDelta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":" Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89",
"value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">Delta Electronics recommends users update to DIAEnergie v1.10.01.004 to mitigate these vulnerabilities. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents.</span>\n\n<br>"
}
],
"value":"\nDelta Electronics recommends users update to DIAEnergie v1.10.01.004 to mitigate these vulnerabilities. Users can request this version of DIAEnergie from Delta Electronics' regional sales or agents.\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Michael Heinzl reported these vulnerabilities to CISA."