CVE-2021-21916

HIGH

Advantech R-SeeNet 2.4.15 - Authenticated SQL Injection via Group List Description Filter

Title source: llm
STIX 2.1

Description

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1363

Scores

CVSS v3 8.8
EPSS 0.0168
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
advantech/r-seenet 2.4.15
Published Dec 22, 2021
Tracked Since Feb 18, 2026