Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an malicious user to remotely execute code.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
deltaww dialink |