CVE-2021-21937: SQL Injection
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘hostaltfilter’ parameter. This can be done as any authenticated user or through cross-site request forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21937?
CVE-2021-21937 is a vulnerability that allows for SQL injection through a specially-crafted HTTP request.
How can an attacker exploit CVE-2021-21937?
An attacker can exploit CVE-2021-21937 by making authenticated HTTP requests with a specially-crafted payload at the 'host_alt_filter' parameter.
What is the severity of CVE-2021-21937?
The severity of CVE-2021-21937 is high, with a severity value of 6.5.
Which software is affected by CVE-2021-21937?
The Advantech R-SeeNet software version 2.4.15 is affected by CVE-2021-21937.
Is any user at risk?
Yes, any authenticated user is at risk of exploitation, and cross-site request forgery can also be used.