S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-13462 Scanner

CVE-2019-13462 scanner - SQL Injection (SQLi) vulnerability in Lansweeper

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-13462
9.1
CVSS

Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Lansweeper is a popular IT asset management software used by many organizations around the world. It is designed to help businesses keep track of their hardware and software inventory, monitor network devices, and automate IT workflows. With its powerful scanning capabilities, it can detect all of the devices on a network and provide detailed information about them. From servers to printers, Lansweeper can provide a comprehensive view of all the digital assets within an organization.

However, despite its usefulness, Lansweeper was found to have a critical vulnerability in its system - the CVE-2019-13462. This vulnerability allowed attackers to inject malicious SQL queries into Lansweeper without any authentication. As a result, attackers could gain unrestricted access to sensitive information stored in the organization's databases. This could include personally identifiable information (PII), authentication credentials, and other sensitive data. 

If this vulnerability were to be exploited, it could cause serious harm to the organization. Attackers could compromise the confidentiality, integrity, and availability of the data stored in the organization's databases. This could lead to data breaches, financial losses, and reputational damage. Moreover, attackers could use this vulnerability to download malware onto the organization's servers, leading to continuous data theft and exfiltration.

In conclusion, Lansweeper is a valuable tool for IT asset management, but like any software, it is not immune to vulnerabilities. The CVE-2019-13462 vulnerability is a serious threat that organizations should be aware of and take steps to mitigate. At s4e.io, we provide pro features that can help organizations quickly and easily identify vulnerabilities in their digital assets. By using our platform, organizations can ensure that their digital assets are secure and protected against the latest threats.

 

REFERENCES

Solution Advice

To protect against the vulnerability, users of Lansweeper should follow the following precautions:

  • Update Lansweeper to version 7.1.117.4 or above.
  • Restrict Lansweeper’s access to the internet.
  • Restrict access to Lansweeper’s web interface.
  • Deploy a web application firewall.
  • Apply the principle of least privilege to reduce the attack surface.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-13462 scanner - SQL Injection (SQLi) vulnerability in Lansweeper | S4E