A SQLi vulnerability exists in Delta Electronics...
Critical severity
Unreviewed
Published
May 6, 2024
to the GitHub Advisory Database
•
Updated May 6, 2024
Description
Published by the National Vulnerability Database
May 6, 2024
Published to the GitHub Advisory Database
May 6, 2024
Last updated
May 6, 2024
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field
References