VYPR
Unrated severityNVD Advisory· Published Oct 27, 2022· Updated Apr 16, 2025

Delta Electronics DIAEnergie

CVE-2022-40965

Description

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored cross-site scripting in Delta Electronics DIAEnergie's PostEnergyType API allows remote authenticated attackers to inject arbitrary web scripts.

Vulnerability

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API [1]. This improper neutralization of input during web page generation (CWE-79) allows an attacker to inject malicious scripts that are stored on the server and later executed in the context of other users' browsers.

Exploitation

An attacker must have low-privileged access to the DIAEnergie application (authentication required) and convince a victim to interact with the crafted content (user interaction required) [1]. The attacker sends a specially crafted request to the PostEnergyType API endpoint, which stores the malicious payload. When a victim views the affected page, the script executes.

Impact

Successful exploitation leads to high confidentiality and integrity impact, as the attacker can steal session cookies, modify data, or perform actions on behalf of the victim [1]. Availability is not affected. The CVSS v3 base score is 8.7 (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

Mitigation

Delta Electronics has released fixed versions: DIAEnergie v1.9.01.002 and later (including v1.9.02.001 and v1.9.03.001) [1]. Users should update to the latest available version. No workarounds are provided in the advisory.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.