CVE-2022-32763
https://notcve.org/view.php?id=CVE-2022-32763
A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability. Existe una omisión de vulnerabilidad de sanitización de Cross-Site Scripting (XSS) en la funcionalidad SanitizeHtml de Lansweeper lansweeper 10.1.1.0. Una solicitud HTTP especialmente manipulada puede provocar una inyección de código Javascript arbitrario. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1541 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-184: Incomplete List of Disallowed Inputs •
CVE-2022-32573
https://notcve.org/view.php?id=CVE-2022-32573
A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. Existe una vulnerabilidad de directory traversal en la funcionalidad addDoc AssetActions.aspx de Lansweeper lansweeper 10.1.1.0. Una solicitud HTTP especialmente manipulada puede provocar la carga de archivos arbitrarios. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1528 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-29517
https://notcve.org/view.php?id=CVE-2022-29517
A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. Existe una vulnerabilidad de directory traversal en la funcionalidad de edición de plantilla HelpdeskActions.aspx de Lansweeper lansweeper 10.1.1.0. Una solicitud HTTP especialmente manipulada puede provocar la carga de archivos arbitrarios. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1529 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-29511
https://notcve.org/view.php?id=CVE-2022-29511
A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. Existe una vulnerabilidad de directory traversal en la funcionalidad KnowledgebasePageActions.aspx ImportArticles de Lansweeper lansweeper 10.1.1.0. Una solicitud HTTP especialmente manipulada puede provocar la lectura de archivos arbitrarios. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1530 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-28703
https://notcve.org/view.php?id=CVE-2022-28703
A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability. Existe una vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en la funcionalidad altertextlanguages HdConfigActions.aspx de Lansweeper lansweeper 10.1.1.0. Una solicitud HTTP especialmente manipulada puede provocar una inyección de código Javascript arbitrario. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1532 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •