First published: Tue Oct 20 2020(Updated: )
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech R-SeeNet | >=1.5.1<=2.4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25157 is a vulnerability in the R-SeeNet webpage (versions 1.5.1 through 2.4.10) that allows a remote attacker to perform SQL injection.
CVE-2020-25157 has a severity score of 7.5, which is considered high.
The affected software of CVE-2020-25157 is Advantech R-SeeNet versions 1.5.1 through 2.4.10.
CVE-2020-25157 belongs to CWE category 89, which is Improper Neutralization of Special Elements in an SQL Command ('SQL Injection').
To fix CVE-2020-25157, it is recommended to upgrade R-SeeNet to a version beyond 2.4.10 or apply a patch provided by Advantech.