Record summary

CVE-2021-21802 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Advantech

CVE ListAdvantech R-SeeNet 2.4.12 (20.10.2020)affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAdvantech R-SeeNet - Cross-Site ScriptingCVSS 6.1

Advantech R-SeeNet contains a cross-site scripting vulnerability in the device_graph_page.php script via the device_id parameter. A specially crafted URL by an attacker can lead to arbitrary JavaScript code execution.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by Advantech to fix the XSS vulnerability in the R-SeeNet application.

WeaknessesCWE-79
Authorsgy741
Template tagscve2021cverseenetxssadvantechvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:advantech:r-seenet:2.4.12:*:*:*:*:*:*:*
Shodan: http.html:"r-seenet"
FOFA: body="r-seenet"

Source: ProjectDiscovery

References

2