CVE-2021-38488

MEDIUM

Delta Electronics DIALink <1.2.4.0 - XSS

Title source: llm
STIX 2.1

Description

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02

Scores

CVSS v3 5.5
EPSS 0.0063
EPSS Percentile 70.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
deltaww/dialink < 1.2.4.0
Published Nov 03, 2021
Tracked Since Feb 18, 2026