First published: Wed Nov 03 2021(Updated: )
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.2.4.0 | |
Delta Electronics DIALink | <=1.2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Delta Electronics DIALink vulnerability is CVE-2021-38403.
The severity level of the Delta Electronics DIALink vulnerability is medium (4.8).
The Delta Electronics DIALink vulnerability allows an authenticated attacker to inject arbitrary JavaScript code into the parameter supplier of the API maintenance, enabling remote code execution.
To fix the Delta Electronics DIALink vulnerability, update to a version newer than 1.2.4.0.
More information about the Delta Electronics DIALink vulnerability can be found at the following link: https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02