PT-2021-8992 · Solarwinds · Solarwinds Web Help Desk
Published
2021-01-06
·
Updated
2021-07-21
·
CVE-2019-16954
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SolarWinds Web Help Desk version 12.7.0
Description
The issue allows HTML injection via a Comment in a Help Request ticket. This can potentially lead to malicious activities such as stealing user sessions or conducting phishing attacks.
Recommendations
For SolarWinds Web Help Desk version 12.7.0, consider disabling the comment feature in Help Request tickets until a patch is available to prevent potential HTML injection attacks.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Web Help Desk