First published: Wed Nov 03 2021(Updated: )
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.2.4.0 | |
Delta Electronics DIALink | <=1.2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38428.
The severity of CVE-2021-38428 is medium (4.8).
Delta Electronics DIALink versions 1.2.4.0 and prior are affected by CVE-2021-38428.
CVE-2021-38428 is a cross-site scripting (XSS) vulnerability.
An authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, allowing remote code execution.