← Vulnerability feed

Vulnerability record · CVE-2021-31558 · published 22 December 2021

CVE-2021-31558: Deltaww diaenergie cross-site scripting vulnerability

Deltaww · Diaenergie

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

6.1 CVSS 3.1 Medium EPSS 11% · top 4.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-21-238-03 Third Party AdvisoryUS Government Resource

Track CVE-2021-31558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4547Deltaww diaenergie improper input validation vulnerabilityA SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp…EPSS 1.9%9.8CVE-2024-4548Deltaww diaenergie improper input validation vulnerabilityAn SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is s…EPSS 29%9.8CVE-2024-25574Deltaww diaenergie sql injection vulnerabilitySQL injection vulnerability exists in GetDIAE_usListParameters.EPSS 8.8%9.8CVE-2022-43774Deltaww diaenergie sql injection vulnerabilityThe HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a…EPSS 0.75%9.8CVE-2022-43775Deltaww diaenergie sql injection vulnerabilityThe HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote…EPSS 21%9.8CVE-2022-3214Deltaww diaenergie hard-coded credentials vulnerabilityDelta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…EPSS 2.0%9.8CVE-2022-1367Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an at…EPSS 19%9.8CVE-2022-1369Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-31558), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.