← Back to browse · API

CVE-2024-4547

Severity
CRITICAL
CVSS
9.8
EPSS
0.01895
Risk score
39.86
CISA KEV
No
PoC
No
Published
2024-05-06
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-44159, GHSA-PX8G-4WJ9-X4P3
Products
Delta Electronics:DIAEnergie 0 ≤1.10.1.8610
Sources
euvd EUVD-2024-44159

Description

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

References