CVE-2022-41701
- EPSS 0.49%
- Veröffentlicht 27.10.2022 21:15:16
- Zuletzt bearbeitet 21.11.2024 07:23:40
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.
CVE-2022-41773
- EPSS 0.5%
- Veröffentlicht 27.10.2022 21:15:16
- Zuletzt bearbeitet 21.11.2024 07:23:49
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
CVE-2022-41555
- EPSS 0.49%
- Veröffentlicht 27.10.2022 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:23:23
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
CVE-2022-41133
- EPSS 0.47%
- Veröffentlicht 27.10.2022 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:22:40
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL quer...
CVE-2022-40967
- EPSS 0.5%
- Veröffentlicht 27.10.2022 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:22:19
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
CVE-2022-40965
- EPSS 0.49%
- Veröffentlicht 27.10.2022 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:22:19
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.
CVE-2022-43775
- EPSS 1.79%
- Veröffentlicht 26.10.2022 18:15:10
- Zuletzt bearbeitet 07.05.2025 14:15:38
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
CVE-2022-43774
- EPSS 0.51%
- Veröffentlicht 26.10.2022 18:15:10
- Zuletzt bearbeitet 07.05.2025 14:15:38
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
CVE-2022-3214
- EPSS 4.85%
- Veröffentlicht 16.09.2022 19:15:10
- Zuletzt bearbeitet 25.02.2026 16:21:25
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain director...
CVE-2022-33005
- EPSS 0.24%
- Veröffentlicht 27.06.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:07:24
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.