CVE-2021-21931: SQL Injection
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ statfilter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21931?
CVE-2021-21931 is a vulnerability that allows for SQL injection through a specially-crafted HTTP request.
How can an attacker exploit CVE-2021-21931?
An attacker can exploit CVE-2021-21931 by making authenticated HTTP requests with a specifically crafted 'stat_filter' parameter.
What is the severity of CVE-2021-21931?
The severity of CVE-2021-21931 is high, with a severity value of 6.5.
Which software version is affected by CVE-2021-21931?
The Advantech R-SeeNet software version 2.4.15 is affected by CVE-2021-21931.
How can I fix CVE-2021-21931?
To fix CVE-2021-21931, it is recommended to update to a version of Advantech R-SeeNet that does not have the vulnerability.