From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:05:09 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 12.2.1.0 (web reports 12.2.1.6)
(Lansweeper). The research is published and a proof-of-concept is available.
Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated)
Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions console. A SQL Server sub-server name
containing a single quote is stored and later concatenated unescaped into a NOT LIKE clause; the query is executed with
stacked statements, enabling EXEC xp_cmdshell. The default lansweeperuser database account is SQL Server sysadmin and
xp_cmdshell is enabled by default, so an authenticated administrator achieves remote code execution. Dynamically
verified.
Impact: Full compromise of the Lansweeper server. The attacker can execute arbitrary commands, read scanned asset and
credential data, and pivot into the managed network.
Advisory: https://0day-rubbish.com/blog/lansweeper-licenseactions-sqli-xpcmdshell-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper) disclosure via Fulldisclosure (Aug 17)