CVE-2021-21929: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prodfilter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21929?
CVE-2021-21929 is a vulnerability that allows for SQL injection through a specially-crafted HTTP request.
2
How can an attacker exploit CVE-2021-21929?
An attacker can exploit CVE-2021-21929 by making authenticated HTTP requests at the 'prod_filter' parameter.
3
What is the severity of CVE-2021-21929?
CVE-2021-21929 has a severity value of 6.5 (high).
4
What software is affected by CVE-2021-21929?
Advantech R-SeeNet version 2.4.15 is affected by CVE-2021-21929.
5
How can CVE-2021-21929 be fixed?
To fix CVE-2021-21929, update to a version of Advantech R-SeeNet that is not affected by the vulnerability.