Vulnerability Description
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lansweeper | Lansweeper | 8.0.130.17 |
Related Weaknesses (CWE)
References
- https://research.nccgroup.com/2020/09/25/technical-advisory-lansweeper-privilegeExploitThird Party Advisory
- https://www.nccgroup.com/us/our-research/?research=Technical+advisoriesThird Party Advisory
- https://research.nccgroup.com/2020/09/25/technical-advisory-lansweeper-privilegeExploitThird Party Advisory
- https://www.nccgroup.com/us/our-research/?research=Technical+advisoriesThird Party Advisory
FAQ
What is CVE-2020-13658?
CVE-2020-13658 is a vulnerability with a CVSS score of 8.0 (HIGH). In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
How severe is CVE-2020-13658?
CVE-2020-13658 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13658?
Check the references section above for vendor advisories and patch information. Affected products include: Lansweeper Lansweeper.