DescriptionDelta Electronics DIAEnergie before 1.11.00.022 contains a path traversal vulnerability in a page method that writes template files, allowing remote unauthenticated attackers to write files outside the intended template directory by injecting directory-traversal sequences into the user-controlled template name parameter. Attackers can leverage the lack of input sanitization and authentication enforcement to place attacker-named files in web-accessible locations, corrupting application files or achieving arbitrary file write on the system.