Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-84840
HistoryOct 22, 2021 - 12:00 a.m.

DIALink Cross-Site Scripting Vulnerability (CNVD-2021-84840)

2021-10-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
3
dialink
cross-site scripting
delta electronics
cnc machines
plc-controlled machines
api event
remote code execution

EPSS

0.001

Percentile

33.0%

DIALink is a device networking platform from Delta Electronics that allows effective management of CNC machines and PLC-controlled machines, collects field device data and interfaces with the upper management platform through a unified interface, and provides visual information to reflect process parameters and device operating status. scripting vulnerability. An attacker can use this vulnerability to inject arbitrary JavaScript code into the comment parameter of an API event, which allows remote code execution.

EPSS

0.001

Percentile

33.0%

Related for CNVD-2021-84840