Full Disclosure mailing list archives
Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)
From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:05:09 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper). The research is published and a proof-of-concept is available. Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated) Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions console. A SQL Server sub-server name containing a single quote is stored and later concatenated unescaped into a NOT LIKE clause; the query is executed with stacked statements, enabling EXEC xp_cmdshell. The default lansweeperuser database account is SQL Server sysadmin and xp_cmdshell is enabled by default, so an authenticated administrator achieves remote code execution. Dynamically verified. Impact: Full compromise of the Lansweeper server. The attacker can execute arbitrary commands, read scanned asset and credential data, and pivot into the managed network. Advisory: https://0day-rubbish.com/blog/lansweeper-licenseactions-sqli-xpcmdshell-rce PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish Vendor has been notified. CVE ID is pending. -- 0day Rubbish Research Team https://0day-rubbish.com _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper) disclosure via Fulldisclosure (Aug 17)
