Description
NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 14.12.0001
Credits
Chris Leech
References
kb.netsupportsoftware.com/...nd-securing-netsupport-manager/
www.vulncheck.com/...uthenticated-sqli-local-file-disclosure
ret2.me/post/2025-12-04-exploiting-netsupport-gateway/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.