CVE-2021-38407: Delta Electronics DIALink
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38407.
What is the severity level of CVE-2021-38407?
The severity level of CVE-2021-38407 is medium.
What is the affected software for CVE-2021-38407?
The affected software for CVE-2021-38407 is Delta Electronics DIALink versions 1.2.4.0 and prior.
What is the description of CVE-2021-38407?
CVE-2021-38407 is a vulnerability in Delta Electronics DIALink that allows an authenticated attacker to inject arbitrary JavaScript code into the parameter name of API devices, potentially allowing remote code execution.
Is there a fix available for CVE-2021-38407?
At the moment, there is no information available about a fix for CVE-2021-38407. It is recommended to follow the guidance provided by the vendor or product team.