Vulnerability CVE-2024-43699


Published: 2024-10-03   Modified: 2024-10-04

Description:
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://www.cisa.gov/news-events/ics-advisories/icsa-24-277-03
https://www.deltaww.com/en-US/Cybersecurity_Advisory

Copyright 2024, cxsecurity.com

 

Back to Top