CVE-2021-21923: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘companyfilter’ parameter with the administrative account or through cross-site request forgery.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21923?
The severity of CVE-2021-21923 is high.
2
How does CVE-2021-21923 work?
CVE-2021-21923 occurs when a specially-crafted HTTP request is made, leading to SQL injection.
3
What is the affected software for CVE-2021-21923?
The affected software for CVE-2021-21923 is Advantech R-SeeNet version 2.4.15.
4
How can an attacker exploit CVE-2021-21923?
An attacker can make authenticated HTTP requests to trigger this vulnerability at the 'company_filter' parameter with the administrative account or through cross-site request forgery.
5
Is there a fix for CVE-2021-21923?
It is recommended to upgrade to a patched version of Advantech R-SeeNet to fix CVE-2021-21923.