STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
References
| Link | Resource |
|---|---|
| http://www.stvs.ch | Product |
| https://www.exploit-db.com/exploits/49482 | Technical Description |
| https://www.vulncheck.com/advisories/stvs-provision-cross-site-request-forgery-add-admin | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5625.php | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Feb 2026, 20:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.stvs.ch - Product | |
| References | () https://www.exploit-db.com/exploits/49482 - Technical Description | |
| References | () https://www.vulncheck.com/advisories/stvs-provision-cross-site-request-forgery-add-admin - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5625.php - Third Party Advisory | |
| First Time |
Stvs provision
Stvs |
|
| CPE | cpe:2.3:a:stvs:provision:5.6:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.8.6:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.9.7:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.9.9:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.9.10:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.7:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.9.1:*:*:*:*:*:*:* cpe:2.3:a:stvs:provision:5.9.0:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
09 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 21:15
Updated : 2026-02-17 20:36
NVD link : CVE-2021-47723
Mitre link : CVE-2021-47723
CVE.ORG link : CVE-2021-47723
JSON object : View
Products Affected
stvs
- provision
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
