CVE-2021-38488
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 12.34% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- deltaww/dialink
- Source
- ics-cert@hq.dhs.gov
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.