CVE-2020-25157: SQL Injection
Published Oct 20, 2020
·Updated
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
Affected Software
1 affected component
Advantech R-SeeNet>=1.5.1<=2.4.10
Event History
Oct 20, 2020
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-25157?
CVE-2020-25157 is a vulnerability in the R-SeeNet webpage (versions 1.5.1 through 2.4.10) that allows a remote attacker to perform SQL injection.
2
How severe is CVE-2020-25157?
CVE-2020-25157 has a severity score of 7.5, which is considered high.
3
What is the affected software of CVE-2020-25157?
The affected software of CVE-2020-25157 is Advantech R-SeeNet versions 1.5.1 through 2.4.10.
4
What is the CWE category of CVE-2020-25157?
CVE-2020-25157 belongs to CWE category 89, which is Improper Neutralization of Special Elements in an SQL Command ('SQL Injection').
5
How can I fix CVE-2020-25157?
To fix CVE-2020-25157, it is recommended to upgrade R-SeeNet to a version beyond 2.4.10 or apply a patch provided by Advantech.