Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21915

Опубликовано: 22 дек. 2021
Источник: nvd
CVSS3: 7.7
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:advantech:r-seenet:2.4.15:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.0125
Низкий

7.7 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 8.8
github
около 4 лет назад

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

EPSS

Процентиль: 79%
0.0125
Низкий

7.7 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89