NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 06:45:00 +0900

Type Values Removed Values Added
First Time appeared Netsupport
Netsupport netsupport Manager
Vendors & Products Netsupport
Netsupport netsupport Manager

Tue, 16 Dec 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 03:30:00 +0900

Type Values Removed Values Added
References

Tue, 16 Dec 2025 00:15:00 +0900

Type Values Removed Values Added
Description NetSupport Manager <= 14.12.0.304 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure. NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
Title NetSupport Manager <= 14.12.0.304 Unauthenticated SQLi Local File Disclosure NetSupport Manager < 14.12.0001 Unauthenticated SQLi Local File Disclosure

Tue, 16 Dec 2025 00:00:00 +0900

Type Values Removed Values Added
Description NetSupport Manager <= 14.12.0.304 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
Title NetSupport Manager <= 14.12.0.304 Unauthenticated SQLi Local File Disclosure
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-15T19:26:51.604Z

Reserved: 2025-04-15T19:15:22.567Z

Link: CVE-2025-34179

cve-icon Vulnrichment

Updated: 2025-12-15T19:26:47.159Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T15:15:49.573

Modified: 2025-12-15T19:16:04.380

Link: CVE-2025-34179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-16T06:33:28Z

Weaknesses