CVE-2021-21803: XSS
Published Jul 16, 2021
·Updated
This vulnerability is present in devicegraphpage.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.12
Event History
Jul 16, 2021
CVE Published
via MITRE·10:37 AM
Data Sourced
via MITRE·10:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21803?
CVE-2021-21803 is a vulnerability present in the device_graph_page.php script of the Advantech R-SeeNet web applications.
2
What can an attacker do with CVE-2021-21803?
An attacker can execute arbitrary JavaScript code by crafting a specially crafted URL and making the victim visit it.
3
Which software versions are affected by CVE-2021-21803?
Advantech R-SeeNet version 2.4.12 is affected by CVE-2021-21803.
4
What is the severity of CVE-2021-21803?
CVE-2021-21803 has a severity rating of critical with a CVSS score of 6.1.
5
Where can I find more information about CVE-2021-21803?
You can find more information about CVE-2021-21803 at the following URL: https://talosintelligence.com/vulnerability_reports/TALOS-2021-1272