First published: Wed Nov 03 2021(Updated: )
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.2.4.0 | |
Delta Electronics DIALink | <=1.2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38407.
The severity level of CVE-2021-38407 is medium.
The affected software for CVE-2021-38407 is Delta Electronics DIALink versions 1.2.4.0 and prior.
CVE-2021-38407 is a vulnerability in Delta Electronics DIALink that allows an authenticated attacker to inject arbitrary JavaScript code into the parameter name of API devices, potentially allowing remote code execution.
At the moment, there is no information available about a fix for CVE-2021-38407. It is recommended to follow the guidance provided by the vendor or product team.