STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
History

Wed, 10 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Stvs
Stvs provision
Vendors & Products Stvs
Stvs provision

Tue, 09 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
Title STVS ProVision Cross-Site Request Forgery (Add Admin)
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-09T20:41:56.364Z

Updated: 2025-12-09T20:41:56.364Z

Reserved: 2025-12-07T14:25:05.584Z

Link: CVE-2021-47723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-09T21:15:50.770

Modified: 2025-12-09T21:15:50.770

Link: CVE-2021-47723

cve-icon Redhat

No data.