Blind SQL Injection in Delta Electronics DIAEnergie Software
CVE-2021-38391
9.8CRITICAL
What is CVE-2021-38391?
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie, specifically in versions 1.7.5 and earlier. This vulnerability arises due to inadequate validation of user-controlled input in the 'type' parameter before it is utilized in SQL queries. As a result, an unauthenticated attacker can exploit this flaw to execute arbitrary SQL commands, potentially gaining access to sensitive information or executing code in the context of NT SERVICE\MSSQLSERVER, leading to significant security risks.
Affected Version(s)
Delta Electronics DIAEnergie DIAEnergie Version 1.7.5 and prior
