CVE-2021-38403

MEDIUM

Delta Electronics DIALink <1.2.4.0 - XSS

Title source: llm
STIX 2.1

Description

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02

Scores

CVSS v3 5.5
EPSS 0.0042
EPSS Percentile 62.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
deltaww/dialink < 1.2.4.0
Published Nov 03, 2021
Tracked Since Feb 18, 2026