CVE-2021-38488: Delta Electronics DIALink
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38488?
The severity of CVE-2021-38488 is medium with a CVSS score of 4.8.
How does CVE-2021-38488 impact Delta Electronics DIALink?
CVE-2021-38488 allows an authenticated attacker to inject arbitrary JavaScript code into the parameter comment of the API events, potentially leading to remote code execution.
How can an attacker exploit CVE-2021-38488?
An attacker can exploit CVE-2021-38488 by injecting malicious JavaScript code into the parameter comment of the API events, targeting vulnerable instances of Delta Electronics DIALink.
Is there a fix available for CVE-2021-38488?
At the moment, there is no fix available for CVE-2021-38488. It is recommended to implement mitigations suggested by the vendor or follow the guidance provided by Delta Electronics.
Where can I find more information about CVE-2021-38488?
You can find more information about CVE-2021-38488 on the official US-CERT website at the following URL: https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02