CVE-2021-21922: SQL Injection
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘usernamefilter’ parameter with the administrative account or through cross-site request forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21922?
CVE-2021-21922 is a vulnerability that allows an attacker to perform SQL injection through a specially-crafted HTTP request.
How does CVE-2021-21922 work?
An attacker can make authenticated HTTP requests to trigger this vulnerability at the 'username_filter' parameter with the administrative account or through cross-site request forgery.
What is the severity of CVE-2021-21922?
The severity of CVE-2021-21922 is high, with a severity score of 6.5.
Which software versions are affected by CVE-2021-21922?
The affected software is Advantech R-SeeNet version 2.4.15.
How can I fix CVE-2021-21922?
To fix CVE-2021-21922, users should apply the necessary software updates or patches provided by Advantech.