Skip to main content

Vendor/product archive

solarwinds / webhelpdesk CVEs

Beta · best-effort

6 CVEs tagged to solarwinds / webhelpdesk0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2021-35254

Published Mar 25, 2022

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this in…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35232

Published Dec 27, 2021

Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execut…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-16959

Published Dec 21, 2020

SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20002

Published Apr 27, 2020

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1