#VU58298 SQL injection in R-SeeNet - CVE-2021-21919
Published: November 23, 2021 / Updated: December 16, 2021
R-SeeNet
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "ord" parameter in "company_list" page. A remote authenticated attacker can send a specially crafted request to the affected application and gain access to sensitive information on the system.