CVE-2021-21920: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surnamefilter’ parameter with the administrative account or through cross-site request forgery.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21920?
CVE-2021-21920 is a vulnerability that can lead to SQL injection through a specially-crafted HTTP request.
2
How does CVE-2021-21920 occur?
CVE-2021-21920 occurs when an attacker makes authenticated HTTP requests with a specially-crafted request to the 'surname_filter' parameter.
3
What software is affected by CVE-2021-21920?
Advantech R-SeeNet version 2.4.15 is affected by CVE-2021-21920.
4
What is the severity of CVE-2021-21920?
The severity of CVE-2021-21920 is high with a CVSS score of 4.9.
5
How can I fix CVE-2021-21920?
To fix CVE-2021-21920, it is recommended to apply the necessary patches or updates provided by Advantech for R-SeeNet version 2.4.15.