Solarwinds

Web Help Desk

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 10.12.2024 09:15:06
  • Zuletzt bearbeitet 25.02.2025 17:20:37

SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.

Warnung Medienbericht
  • EPSS 94.17%
  • Veröffentlicht 21.08.2024 22:15:04
  • Zuletzt bearbeitet 27.10.2025 17:01:42

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Warnung Medienbericht
  • EPSS 76.6%
  • Veröffentlicht 13.08.2024 23:15:16
  • Zuletzt bearbeitet 27.10.2025 17:01:47

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerab...

  • EPSS 0.72%
  • Veröffentlicht 10.03.2022 17:42:38
  • Zuletzt bearbeitet 21.11.2024 06:12:09

Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.

  • EPSS 0.63%
  • Veröffentlicht 23.12.2021 20:15:11
  • Zuletzt bearbeitet 21.11.2024 06:12:08

The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied...

  • EPSS 0.49%
  • Veröffentlicht 26.08.2021 15:15:06
  • Zuletzt bearbeitet 21.11.2024 06:06:48

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network ra...

Exploit
  • EPSS 2.19%
  • Veröffentlicht 15.01.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:31:25

SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.

Exploit
  • EPSS 1.43%
  • Veröffentlicht 06.01.2021 17:15:21
  • Zuletzt bearbeitet 21.11.2024 04:31:24

SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

Exploit
  • EPSS 1.93%
  • Veröffentlicht 04.01.2021 08:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:24

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

Exploit
  • EPSS 1.93%
  • Veröffentlicht 04.01.2021 08:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:25

SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.