Security advisory: Authenticat... Note

Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)

Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper). The research is published and a proof-of-concept is available. Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated) Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions console. A SQL Server sub-server name containing a single quote is stored and later concatenated...