Vulnerabilities > Lansweeper > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-15 CVE-2022-29517 Unspecified vulnerability in Lansweeper 10.1.1.0
A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0.
network
low complexity
lansweeper
8.8
2022-12-15 CVE-2022-32573 Unspecified vulnerability in Lansweeper 10.1.1.0
A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0.
network
low complexity
lansweeper
8.8
2022-04-14 CVE-2022-21210 SQL Injection vulnerability in Lansweeper 9.1.20.2
An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.
network
low complexity
lansweeper CWE-89
8.8
2022-04-14 CVE-2022-21234 SQL Injection vulnerability in Lansweeper 9.1.20.2
An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2.
network
low complexity
lansweeper CWE-89
8.8
2022-04-14 CVE-2022-22149 SQL Injection vulnerability in Lansweeper 9.1.20.2
A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.
network
low complexity
lansweeper CWE-89
8.8
2020-09-30 CVE-2020-13658 Cross-Site Request Forgery (CSRF) vulnerability in Lansweeper 8.0.130.17
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
network
low complexity
lansweeper CWE-352
8.0