Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05023
HistoryDec 19, 2021 - 12:00 a.m.

Delta Electronics DIAEnergie name parameter cross-site scripting vulnerability

2021-12-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
delta electronics
diaenergie
cross-site scripting
vulnerability
industrial energy management
parameter name
javascript code
client side

EPSS

0.001

Percentile

44.2%

Delta Electronics DIAEnergie is an industrial energy management system used to monitor and analyze energy consumption in real time, calculate energy consumption and load characteristics, optimize equipment performance, improve production processes, and maximize energy efficiency.A cross-site scripting vulnerability exists in Delta Electronics DIAEnergie, which stems from The parameter name of “DIAE_hierarchyHandler.ashx” filters the user-supplied data and output data checks. An attacker could use this vulnerability to execute JavaScript code on the client side

EPSS

0.001

Percentile

44.2%