CVE-2021-21930: SQL Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘snfilter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
Affected Software
1 affected component
Advantech R-SeeNet=2.4.15
Event History
Dec 22, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21930?
CVE-2021-21930 is a vulnerability that allows SQL injection through a specially-crafted HTTP request.
2
How does CVE-2021-21930 occur?
CVE-2021-21930 can occur when an attacker makes authenticated HTTP requests with a manipulated 'sn_filter' parameter.
3
What is the severity of CVE-2021-21930?
CVE-2021-21930 has a severity rating of high with a CVSS score of 6.5.
4
Which software versions are affected by CVE-2021-21930?
Advantech R-SeeNet version 2.4.15 is affected by CVE-2021-21930.
5
How can CVE-2021-21930 be exploited?
CVE-2021-21930 can be exploited by an attacker performing authenticated HTTP requests with a manipulated 'sn_filter' parameter.