Impact
This vulnerability is a classic SQL injection flaw that allows an attacker to submit crafted SQL statements through user-controlled input channels in DIAEnergie. Exploitation can lead to unauthorized data read, update, or deletion against the underlying database, compromising confidentiality and integrity of stored information. The weakness is classified as CWE-89.
Affected Systems
Products affected are Deltaww DIAEnergie running any version earlier than 1.11.00.022. The vulnerability exists in all releases before that tag, regardless of deployment size.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. Because the EPSS score is not provided, the probability of exploitation cannot be precisely quantified, but a typical SQL injection provides an easy path for attackers once the vulnerable input is reachable, often without authentication. The fixed version is not listed in CISA KEV, suggesting no known public exploits at this time.
OpenCVE Enrichment