Files
CVEs-PoC/2021/CVE-2021-21918.md
2025-09-29 21:09:30 +02:00

18 lines
990 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
### [CVE-2021-21918](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21918)
![](https://img.shields.io/static/v1?label=Product&message=Advantech&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=Advantech%20R-SeeNet%20Advantech%20R-SeeNet%202.4.15%20(30.07.2021)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%3A%20Improper%20Neutralization%20of%20Special%20Elements%20used%20in%20an%20SQL%20Command%20('SQL%20Injection')&color=brightgreen)
### Description
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at name_filter parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack.
### POC
#### Reference
- https://talosintelligence.com/vulnerability_reports/TALOS-2021-1364
#### Github
No PoCs found on GitHub currently.