← Back to browse · API

CVE-2022-21234

Severity
CRITICAL
CVSS
9.1
EPSS
0.72601
Risk score
61.81
CISA KEV
No
PoC
No
Published
2022-04-14
Modified
2025-04-15
First seen
2026-08-07
Aliases
EUVD-2022-26460, GHSA-6F4M-7XVC-GVWR
Products
Lansweeper:lansweeper 9.1.20.2
Sources
euvd EUVD-2022-26460

Description

An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

References