CVE-2021-47723

HIGH

STVS ProVision 5.9.10 - CSRF

Title source: llm

Description

STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · htmlwebappsruby
https://www.exploit-db.com/exploits/49482

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-352
Status published

Affected Products (9)

stvs/provision
stvs/provision
stvs/provision
stvs/provision
stvs/provision
stvs/provision
stvs/provision
stvs/provision
stvs/provision

Timeline

Published Dec 09, 2025
Tracked Since Feb 18, 2026