CVE Database
/

CVE-2021-38390

Back to search

CVE-2021-38390

Published: Aug 30, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

VendorProductVersions

n/a

Delta Electronics DIAEnergie

affected
DIAEnergie Version 1.7.5 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now