Skip to content
Noroxi

Lansweeper records

18 published records for vendor lansweeper.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

18 records
  • A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    HighCVSS 8.8No exploitEPSS 73%

    lansweeper · lansweeperApr 14, 2022

  • An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    HighCVSS 8.8No exploitEPSS 73%

    lansweeper · lansweeperApr 14, 2022

  • An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    HighCVSS 8.8No exploitEPSS 71%

    lansweeper · lansweeperApr 14, 2022

  • A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0.

    HighCVSS 8.8No exploitEPSS 58%

    lansweeper · lansweeperDec 15, 2022

  • Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in

    CriticalCVSS 9.8Proof of conceptEPSS 29%

    lansweeper · lansweeperJun 15, 2020

  • A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.

    MediumCVSS 4.8No exploitEPSS 78%

    lansweeper · lansweeperApr 14, 2022

  • XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows

    CriticalCVSS 9.9No exploitEPSS 2%

    lansweeper · lansweeperOct 10, 2017

  • Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windo

    CriticalCVSS 9.8No exploitEPSS 2%

    lansweeper · lansweeperAug 27, 2018

  • Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

    CriticalCVSS 9.1Proof of conceptEPSS 11%

    lansweeper · lansweeperAug 12, 2019

  • A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10

    MediumCVSS 6.5No exploitEPSS 38%

    lansweeper · lansweeperDec 15, 2022

  • A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0.

    HighCVSS 8.8No exploitEPSS 4%

    lansweeper · lansweeperDec 15, 2022

  • In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privi

    HighCVSS 8.0No exploitEPSS 0%

    lansweeper · lansweeperSep 30, 2020

  • A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1

    MediumCVSS 6.5No exploitEPSS 2%

    lansweeper · lansweeperDec 15, 2022

  • LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    lansweeper · lansweeperNov 15, 2017

  • A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0.

    MediumCVSS 6.1No exploitEPSS 1%

    lansweeper · lansweeperDec 15, 2022

  • CVE-2017-9292
    24Monitor

    Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.

    MediumCVSS 6.1No exploitEPSS 1%

    lansweeper · lansweeperMay 29, 2017

  • The web console in Lansweeper 7.2.105.2 has XSS via the URL path.

    MediumCVSS 6.1No exploitEPSS 1%

    lansweeper · lansweeperDec 19, 2019

  • A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.

    MediumCVSS 5.4No exploitEPSS 1%

    lansweeper · lansweeperDec 15, 2022