[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Tue, 18 Aug 2026 06:05:09 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper
12.2.1.0 (web reports 12.2.1.6) (Lansweeper). The research is published and a
proof-of-concept is available.
Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated)
Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions
console. A SQL Server sub-server name containing a single quote is stored and
later concatenated unescaped into a NOT LIKE clause; the query is executed with
stacked statements, enabling EXEC xp_cmdshell. The default lansweeperuser
database account is SQL Server sysadmin and xp_cmdshell is enabled by default,
so an authenticated administrator achieves remote code execution. Dynamically
verified.
Impact: Full compromise of the Lansweeper server. The attacker can execute
arbitrary commands, read scanned asset and credential data, and pivot into the
managed network.
Advisory:
https://0day-rubbish.com/blog/lansweeper-licenseactions-sqli-xpcmdshell-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/