CVE-2021-21925: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘firmfilter’ parameter.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21925?
CVE-2021-21925 is a vulnerability that allows a specially-crafted HTTP request to lead to SQL injection.
2
How can CVE-2021-21925 be exploited?
CVE-2021-21925 can be exploited by making authenticated HTTP requests with a specially-crafted payload.
3
What is the severity of CVE-2021-21925?
CVE-2021-21925 has a severity rating of 6.5 (high).
4
What software versions are affected by CVE-2021-21925?
CVE-2021-21925 affects Advantech R-SeeNet version 2.4.15.
5
How can I mitigate the risk of CVE-2021-21925?
To mitigate the risk of CVE-2021-21925, apply the recommended security patches or updates provided by Advantech.