CVE-2021-21802
Advantech R-SeeNet - Cross-Site Scripting
Record summary
CVE-2021-21802 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Advantech | CVE List | Advantech R-SeeNet 2.4.12 (20.10.2020) | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAdvantech R-SeeNet - Cross-Site ScriptingCVSS 6.1
Advantech R-SeeNet contains a cross-site scripting vulnerability in the device_graph_page.php script via the device_id parameter. A specially crafted URL by an attacker can lead to arbitrary JavaScript code execution.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patches or updates provided by Advantech to fix the XSS vulnerability in the R-SeeNet application.
Source: ProjectDiscovery