CVE-2021-47723

STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.6:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.7:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.8.6:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.0:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.1:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.7:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.9:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.10:*:*:*:*:*:*:*

History

17 Feb 2026, 20:36

Type Values Removed Values Added
References () http://www.stvs.ch - () http://www.stvs.ch - Product
References () https://www.exploit-db.com/exploits/49482 - () https://www.exploit-db.com/exploits/49482 - Technical Description
References () https://www.vulncheck.com/advisories/stvs-provision-cross-site-request-forgery-add-admin - () https://www.vulncheck.com/advisories/stvs-provision-cross-site-request-forgery-add-admin - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5625.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5625.php - Third Party Advisory
First Time Stvs provision
Stvs
CPE cpe:2.3:a:stvs:provision:5.6:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.8.6:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.7:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.9:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.10:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.7:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.1:*:*:*:*:*:*:*
cpe:2.3:a:stvs:provision:5.9.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

09 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 21:15

Updated : 2026-02-17 20:36


NVD link : CVE-2021-47723

Mitre link : CVE-2021-47723

CVE.ORG link : CVE-2021-47723


JSON object : View

Products Affected

stvs

  • provision
CWE
CWE-352

Cross-Site Request Forgery (CSRF)