CVE-2021-47723
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-09
Last updated on: 2026-02-17
Assigner: VulnCheck
Description
Description
STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| stvs | provision | 5.5 |
| stvs | provision | 5.6 |
| stvs | provision | 5.7 |
| stvs | provision | 5.8.6 |
| stvs | provision | 5.9.0 |
| stvs | provision | 5.9.1 |
| stvs | provision | 5.9.10 |
| stvs | provision | 5.9.7 |
| stvs | provision | 5.9.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |