PT-2020-9846 · Solarwinds · Solarwinds Web Help Desk

Published

2020-12-18

·

Updated

2020-12-18

·

CVE-2019-16955

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds Web Help Desk version 12.7.0
Description The issue allows for cross-site scripting (XSS) via an uploaded SVG document in a request. This means an attacker could potentially inject malicious scripts into the system by uploading a specially crafted SVG file.
Recommendations For SolarWinds Web Help Desk version 12.7.0, consider disabling the ability to upload SVG documents until a patch is available to prevent potential XSS attacks. Restrict access to the upload feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16955

Affected Products

Solarwinds Web Help Desk