Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05026
HistoryDec 19, 2021 - 12:00 a.m.

Delta Electronics DIAEnergie HandlerEnergyType Parameter Name Cross-Site Scripting Vulnerability

2021-12-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
delta electronics
diaenergie
handlerenergytype
xss
vulnerability
energy management system
real time monitoring
energy consumption
equipment performance
production processes
energy efficiency
javascript code
client side attack

EPSS

0.001

Percentile

42.1%

Delta Electronics DIAEnergie is an industrial energy management system used to monitor and analyze energy consumption in real time, calculate energy consumption and load characteristics, optimize equipment performance, improve production processes, and maximize energy efficiency.A cross-site scripting vulnerability exists in Delta Electronics DIAEnergie, which stems from HandlerEnergyType’s parameter names are filtered against user-supplied data and output data checks. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

42.1%