← Back to browse · API

CVE-2021-21800

Severity
CRITICAL
CVSS
9.6
EPSS
0.14115
Risk score
43.34
CISA KEV
No
PoC
No
Published
2021-07-16
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-8972, GHSA-XHC7-QP6W-XMWM
Products
n/a:Advantech Advantech R-SeeNet 2.4.12 (20.10.2020)
Sources
euvd EUVD-2021-8972

Description

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

References