CVE-2021-21927: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘locfilter’ parameter.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-21927.
2
What is the severity of CVE-2021-21927?
CVE-2021-21927 has a severity rating of 6.5 (high).
3
How can an attacker exploit CVE-2021-21927?
An attacker can exploit CVE-2021-21927 by sending a specially-crafted HTTP request to trigger SQL injection.
4
Who can be targeted by an attacker exploiting CVE-2021-21927?
Any authenticated user or through cross-site request forgery can be targeted by an attacker exploiting CVE-2021-21927.
5
Is there a fix available for CVE-2021-21927?
The vendor may have released a fix for CVE-2021-21927. It is recommended to check with the vendor or apply any available patches or updates.