#VU58313 SQL injection in R-SeeNet - CVE-2021-21923
Published: November 23, 2021 / Updated: December 16, 2021
R-SeeNet
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "company_filter" parameter in "user_list" page. A remote attacker can send a specially crafted request to the affected application and gain access to sensitive information on the system.