Record summary

CVE-2019-13462 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALLansweeper Unauthenticated SQL InjectionCVSS 9.1

Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

Impact

This vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire Lansweeper system.

Remediation

Apply the latest security patch or update provided by Lansweeper to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsdivya_mudgal
Template tagscvecve2019sqlilansweepervkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:lansweeper:lansweeper:*:*:*:*:*:*:*:*
Shodan: http.title:"lansweeper - login"
FOFA: title="lansweeper - login"
Google: intitle:"lansweeper - login"

Source: ProjectDiscovery

References

3