CVE-2021-21924: SQL Injection
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘descfilter’ parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21924?
CVE-2021-21924 is a vulnerability that allows an attacker to perform SQL injection by sending a specially-crafted HTTP request.
How does CVE-2021-21924 work?
CVE-2021-21924 can be exploited by making authenticated HTTP requests with a malicious payload or through cross-site request forgery at the 'desc_filter' parameter.
Who is affected by CVE-2021-21924?
The vulnerability affects users of Advantech R-SeeNet version 2.4.15.
What is the severity of CVE-2021-21924?
CVE-2021-21924 has a severity score of 6.5, which is considered high.
How can I fix CVE-2021-21924?
To fix CVE-2021-21924, it is recommended to update to a patched version of Advantech R-SeeNet.