CVE-2021-21936: SQL Injection
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘healthaltfilter’ parameter. This can be done as any authenticated user or through cross-site request forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21936?
CVE-2021-21936 is a vulnerability that allows for SQL injection through a specially-crafted HTTP request at the 'health_alt_filter' parameter in Advantech R-SeeNet version 2.4.15.
How severe is CVE-2021-21936?
CVE-2021-21936 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2021-21936?
CVE-2021-21936 affects Advantech R-SeeNet version 2.4.15.
How can an attacker exploit CVE-2021-21936?
An attacker can exploit CVE-2021-21936 by making authenticated HTTP requests or through cross-site request forgery to trigger the vulnerability.
Is there a fix for CVE-2021-21936?
To fix CVE-2021-21936, it is recommended to update Advantech R-SeeNet to a version that is not affected by the vulnerability.