High severity8.8NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2021-47723
CVE-2021-47723
Description
STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.6:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.7:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.10:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.9:*:*:*:*:*:*:*
- (no CPE)range: =5.9.10
- STVS SA/STVS ProVisionv5Range: 5.9.10 (build 2885-3a8219a)
Patches
Vulnerability mechanics
References
4- www.vulncheck.com/advisories/stvs-provision-cross-site-request-forgery-add-adminnvdThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5625.phpnvdThird Party Advisory
- www.stvs.chnvdProduct
- www.exploit-db.com/exploits/49482nvdTechnical Description
News mentions
0No linked articles in our index yet.