PT-2025-50244 · Unknown · Stvs Provision

Published

2025-12-09

·

Updated

2026-02-17

·

CVE-2021-47723

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions STVS ProVision version 5.9.10
Description The software contains a cross-site request forgery issue. This allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. An attacker can create new administrative users by tricking a user into visiting a malicious website that triggers the forged request.
Recommendations Apply input validation to all HTTP requests.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47723

Affected Products

Stvs Provision