Vulnerability record · CVE-2022-21210 · published 14 April 2022
CVE-2022-21210: Lansweeper AssetActions.aspx SQL injection
Lansweeper · Lansweeper
Lansweeper 9.1.20.2 contains a SQL injection flaw in the AssetActions.aspx functionality. A specially crafted HTTP request lets an authenticated attacker inject SQL into backend queries, which matters because it can expose or alter the asset database.
Description
An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity, and availability impact, and a very high EPSS score, though exploitation requires authentication.
What it is
Lansweeper 9.1.20.2 contains a SQL injection flaw in the AssetActions.aspx functionality. A specially crafted HTTP request lets an authenticated attacker inject SQL into backend queries, which matters because it can expose or alter the asset database.
Impact
An attacker with a valid account can read, modify, or delete data reachable by the application's database account, and potentially execute database-level commands depending on privileges.
Attack surface
Reached over the network via HTTP requests to AssetActions.aspx; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.712 (99.4th percentile) and the Talos reference is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Lansweeper to a version newer than 9.1.20.2 per the vendor changelog.
- Restrict access to the Lansweeper web interface to trusted networks or VPN.
- Review and minimize database privileges used by the Lansweeper application account.
- Audit accounts with access to AssetActions.aspx and remove unnecessary users.
Detection
- Monitor web logs for unusual or malformed requests to AssetActions.aspx.
- Alert on SQL error strings or unexpected query patterns in Lansweeper application logs.
- Baseline normal AssetActions.aspx request parameters and flag deviations.
- Watch for anomalous database reads or writes originating from the Lansweeper service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1444 | ExploitThird Party Advisory |
| https://www.lansweeper.com/changelog/ | Release NotesVendor Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1444 | ExploitThird Party Advisory |
| https://www.lansweeper.com/changelog/ | Release NotesVendor Advisory |
Track CVE-2022-21210 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21210), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.