Impact
SQL injection in Delta DIAEnergie v1.11.00.002 allows an attacker to inject arbitrary SQL statements. By exploiting unsanitized input fields the attacker can manipulate database queries and ultimately execute code on the host system, leading to full compromise of confidentiality, integrity, and availability. The weakness is a classic input validation flaw represented by CWE‑89.
Affected Systems
Affected vendor is Delta, product DIAEnergie. The vulnerability applies to version v1.11.00.002 and earlier releases, with the fix available in v1.11.00.022 or later. No other affected versions are listed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, and the EPSS score is not currently available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, but the possibility of remote exploitation via a web interface makes it a high‑risk threat. An attacker could construct a malicious request containing injected SQL syntax, causing the application to run unintended database commands that bypass authentication or trigger system calls for code execution.
OpenCVE Enrichment