PT-2021-8993 · Solarwinds · Solarwinds Web Help Desk

Published

2021-01-04

·

Updated

2021-01-06

·

CVE-2019-16956

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds Web Help Desk version 12.7.0
Description The issue allows for cross-site scripting (XSS) attacks via the Request Type parameter of a ticket. This means an attacker could potentially inject malicious scripts into the website, affecting users who access the vulnerable page.
Recommendations For SolarWinds Web Help Desk version 12.7.0, update to a version that fixes this issue to prevent XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Request Type parameter to minimize the risk of exploitation.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16956

Affected Products

Solarwinds Web Help Desk