[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)



0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 
12.2.1.0 (web reports 12.2.1.6) (Lansweeper). The research is published and a 
proof-of-concept is available.

Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated)

Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions 
console. A SQL Server sub-server name containing a single quote is stored and 
later concatenated unescaped into a NOT LIKE clause; the query is executed with 
stacked statements, enabling EXEC xp_cmdshell. The default lansweeperuser 
database account is SQL Server sysadmin and xp_cmdshell is enabled by default, 
so an authenticated administrator achieves remote code execution. Dynamically 
verified.

Impact: Full compromise of the Lansweeper server. The attacker can execute 
arbitrary commands, read scanned asset and credential data, and pivot into the 
managed network.

Advisory: 
https://0day-rubbish.com/blog/lansweeper-licenseactions-sqli-xpcmdshell-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/