Record summary

CVE-2021-21801 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Advantech

CVE ListAdvantech R-SeeNet 2.4.12 (20.10.2020)affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAdvantech R-SeeNet - Cross-Site ScriptingCVSS 6.1

Advantech R-SeeNet contains a cross-site scripting vulnerability in the device_graph_page.php script via the graph parameter. A specially crafted URL by an attacker can lead to arbitrary JavaScript code execution.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by Advantech to fix the XSS vulnerability in the R-SeeNet application.

WeaknessesCWE-79
Authorsgy741
Template tagscve2021cverseenetxssgraphadvantechvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:advantech:r-seenet:2.4.12:*:*:*:*:*:*:*
Shodan: http.html:"r-seenet"
FOFA: body="r-seenet"

Source: ProjectDiscovery

References

2