CVE-2021-38428: Delta Electronics DIALink
Published Nov 3, 2021
·Updated
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.
Affected Software
2 affected components
Delta Electronics DIALink<=1.2.4.0
Deltaww Dialink<=1.2.4.0
Event History
Nov 3, 2021
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-38428.
2
What is the severity of CVE-2021-38428?
The severity of CVE-2021-38428 is medium (4.8).
3
What software versions are affected by CVE-2021-38428?
Delta Electronics DIALink versions 1.2.4.0 and prior are affected by CVE-2021-38428.
4
What is the vulnerability type of CVE-2021-38428?
CVE-2021-38428 is a cross-site scripting (XSS) vulnerability.
5
How can an attacker exploit CVE-2021-38428?
An authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, allowing remote code execution.