PT-2021-8992 · Solarwinds · Solarwinds Web Help Desk

Published

2021-01-06

·

Updated

2021-07-21

·

CVE-2019-16954

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds Web Help Desk version 12.7.0
Description The issue allows HTML injection via a Comment in a Help Request ticket. This can potentially lead to malicious activities such as stealing user sessions or conducting phishing attacks.
Recommendations For SolarWinds Web Help Desk version 12.7.0, consider disabling the comment feature in Help Request tickets until a patch is available to prevent potential HTML injection attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16954

Affected Products

Solarwinds Web Help Desk