Blind SQL Injection Vulnerability in Delta Electronics DIAEnergie Software
CVE-2021-38390
9.8CRITICAL
What is CVE-2021-38390?
A Blind SQL Injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics' DIAEnergie software. The software fails to adequately validate user-input values through the 'egyid' parameter before incorporating them into SQL queries, making it susceptible to exploitation. This allows a remote, unauthenticated attacker to execute arbitrary SQL commands, potentially leading to unauthorized access and manipulation of sensitive data in the context of the NT SERVICE\MSSQLSERVER account.
Affected Version(s)
Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior
