#VU58316 SQL injection in R-SeeNet - CVE-2021-21927
Published: November 23, 2021 / Updated: December 16, 2021
R-SeeNet
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "loc_filter" parameter in the "device_list" page. A remote authenticated attacker can send a specially crafted request to the affected application and gain access to sensitive information on the system.