cve-2021-47795

MEDIUM CVSS 6.2 opencve
Description

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

Timeline
Published
2026-01-16 00:16 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N mitre
3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N mitre
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X nvd
3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N nvd
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N opencve
3.1 6.2 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2021-47795",
  "enrichment": {
    "created": "2026-01-16T13:42:08.516314+00:00",
    "updated": "2026-01-16T13:42:08.516342+00:00",
    "vendors": [
      "geovision",
      "geovision$PRODUCT$geowebserver"
    ]
  },
  "epss": {
    "score": 0.02865
  },
  "mitre": {
    "cpes": [],
    "created": "2026-01-15T23:25:44.158000+00:00",
    "description": "GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.2,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "cvssV4_0": {
        "score": 8.7,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
      }
    },
    "mitre_repo_path": "cves/2021/47xxx/CVE-2021-47795.json",
    "references": [
      "https://www.exploit-db.com/exploits/50211",
      "https://www.geovision.com.tw/cyber_security.php",
      "https://www.vulncheck.com/advisories/geovision-geowebserver-local-file-inclusion"
    ],
    "title": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion",
    "updated": "2026-04-07T14:06:12.212000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-22"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2026-01-16T00:16:23.570000+00:00",
    "description": "GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.2,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "cvssV4_0": {
        "score": 8.7,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2021/CVE-2021-47795.json",
    "references": [
      "https://www.exploit-db.com/exploits/50211",
      "https://www.geovision.com.tw/cyber_security.php",
      "https://www.vulncheck.com/advisories/geovision-geowebserver-local-file-inclusion"
    ],
    "title": null,
    "updated": "2026-06-17T04:18:30.483000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-22"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-01-15T23:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-22"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://www.exploit-db.com/exploits/50211",
                "https://www.geovision.com.tw/cyber_security.php",
                "https://www.vulncheck.com/advisories/geovision-geowebserver-local-file-inclusion"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6.2,
                  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                },
                "cvssV4_0": {
                  "score": 8.7,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "85fa126a-b1da-4fba-b167-67f0e2769740"
      },
      {
        "created": "2026-01-16T14:15:00+00:00",
        "data": [
          {
            "details": [
              "geovision",
              "geovision$PRODUCT$geowebserver"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "geovision",
                "geovision$PRODUCT$geowebserver"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "5b2a944a-1ae4-46b9-b64f-a981542a2b3d"
      },
      {
        "created": "2026-01-16T16:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "poc",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "4a96fd08-1818-40e7-9dcd-98ea7b3aa8bd"
      }
    ],
    "cpes": {
      "data": [],
      "providers": []
    },
    "created": {
      "data": "2026-01-15T23:25:44.158000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6.2,
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {
          "score": 8.7,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.02865
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "poc",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.exploit-db.com/exploits/50211",
        "https://www.geovision.com.tw/cyber_security.php",
        "https://www.vulncheck.com/advisories/geovision-geowebserver-local-file-inclusion"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-15T00:35:42.020000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "geovision",
        "geovision$PRODUCT$geowebserver"
      ],
      "providers": [
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-22"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-01-15T23:25:44.158000+00:00",
    "description": "GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "poc",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion",
    "updated": "2026-01-16T16:07:15.663000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2021/47xxx/CVE-2021-47795.json",
    "weaknesses": []
  }
}
Enrichment data
Nuclei templates
Aggregated bundle (all enrichments)
View JSON API Download JSON