6.5
CVE-2025-26400
- EPSS 0.24%
- Veröffentlicht 29.07.2025 08:07:38
- Zuletzt bearbeitet 17.11.2025 16:11:59
- Quelle psirt@solarwinds.com
- CVE-Watchlists
- Unerledigt
SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solarwinds ≫ Web Help Desk Version < 12.8.7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| psirt@solarwinds.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26400
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7_release_notes.htm