Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-13658
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
0
Attacker Value
Unknown
CVE-2020-14011
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments features.
0
Attacker Value
Unknown
CVE-2019-13462
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
0
Attacker Value
Unknown
CVE-2019-18955
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.
0
Attacker Value
Unknown
CVE-2015-9264
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service.
0
Attacker Value
Unknown
CVE-2017-16841
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
0
Attacker Value
Unknown
CVE-2017-13706
Disclosure Date: October 10, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.
0
Attacker Value
Unknown
CVE-2017-9292
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.
0