CVE-2021-47795 - CVE House
Back to Database
Status published High CVE-2021-47795

GeoVision Geowebserver 5.3.3 - Local FIle Inclusion

Vulnerability Description

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47795

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Ken 's1ngular1ty' Pyle

Affected Vendor

Affected Software

GeoVision Geowebserver
Vulnerable Versions:
<= 5.3.3

Timeline

Official Publish: January 15th, 2026
Last Modified: April 7th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)