Back to search
CVE-2021-47723
Published: Dec 9, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
| Vendor | Product | Versions |
|---|---|---|
STVS SA | STVS ProVision | affected 5.9.10 (build 2885-3a8219a) |
Weaknesses (CWE)
References
ExploitDB-49482
exploit
STVS SA Homepage
product
Zero Science Lab Disclosure (ZSL-2021-5625)
third-party-advisory
VulnCheck Advisory: STVS ProVision Cross-Site Request Forgery (Add Admin)
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now