Vulnerability record · CVE-2022-21145 · published 14 April 2022
CVE-2022-21145: Lansweeper WebUserActions.aspx stored cross-site scripting
Lansweeper · Lansweeper
Lansweeper 9.1.20.2 contains a stored cross-site scripting flaw in the WebUserActions.aspx functionality. A crafted HTTP request can inject arbitrary JavaScript that is stored and later executed in a victim's browser. Because the injected script runs in the application's origin, it can act with the victim's session privileges.
Description
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (4.8) and exploitation requires high privileges plus user interaction, though the very high EPSS and public exploit reference raise concern.
What it is
Lansweeper 9.1.20.2 contains a stored cross-site scripting flaw in the WebUserActions.aspx functionality. A crafted HTTP request can inject arbitrary JavaScript that is stored and later executed in a victim's browser. Because the injected script runs in the application's origin, it can act with the victim's session privileges.
Impact
An attacker can execute arbitrary JavaScript in the browser of a user who views the affected page, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
The flaw is reachable over the network via an HTTP request to WebUserActions.aspx. The vector requires high privileges (PR:H) and user interaction (UI:R), so an authenticated high-privileged user must be induced to trigger or view the injected content.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.77778, 99.5th percentile) and the Talos reference is tagged Exploit, indicating public exploit detail exists, but the record does not confirm active exploitation.
What to do
- Upgrade Lansweeper to a version later than 9.1.20.2 per the vendor changelog.
- Restrict access to the Lansweeper web console to trusted administrators and networks.
- Apply input validation and output encoding to WebUserActions.aspx parameters if patching is delayed.
- Deploy a WAF rule to block script payloads targeting WebUserActions.aspx.
- Review and remove any stored malicious content in user action records.
Detection
- Monitor web logs for suspicious or script-like payloads sent to WebUserActions.aspx.
- Alert on unexpected JavaScript or HTML tags appearing in stored user action data.
- Hunt for anomalous authenticated sessions performing actions inconsistent with the user's role.
- Review Lansweeper audit logs for unusual high-privileged account activity around user action pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1442 | ExploitThird Party Advisory |
| https://www.lansweeper.com/changelog/ | Release NotesVendor Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1442 | ExploitThird Party Advisory |
| https://www.lansweeper.com/changelog/ | Release NotesVendor Advisory |
Track CVE-2022-21145 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21145), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.