CVE-2019-16954
SolarWinds Web Help Desk vulnerability analysis and mitigation

Overview

SolarWinds Web Help Desk 12.7.0 contains an HTML injection vulnerability (CVE-2019-16954) that allows HTML injection via a Comment in a Help Request ticket. The vulnerability was discovered by Abhinav Khanna from eSec Forte Technologies and was reported to MITRE (MITRE CVE, NVD).

Technical details

The vulnerability is classified as a type of injection vulnerability where a user can control an input point and inject arbitrary HTML code into a vulnerable web page. The CVSS v3.1 base score is 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerability is related to improper neutralization of input during web page generation (CWE-79) (NVD).

Impact

The vulnerability can lead to disclosure of user's session cookies and modification of page content seen by victims. It can potentially be chained with CSRF attacks to increase the impact (eSec Forte).

Exploitability

The vulnerability exists in the Comment functionality of Help Request tickets. An authenticated user with access to the ticketing system can exploit this by submitting HTML code in the Comment field of a ticket. The exploitation has been confirmed in version 12.7.0 of the Web Help Desk software (eSec Forte).

Mitigation and workarounds

The primary recommendation is to filter metacharacters from user input. Organizations should ensure they are not running the vulnerable version (12.7.0) of SolarWinds Web Help Desk and update to a patched version (SolarWinds Advisory).

Additional resources


SourceThis report was generated using AI

Related SolarWinds Web Help Desk vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28323CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJul 30, 2026
CVE-2025-40554CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2025-40553CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2025-40552CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2026-28299HIGH7.5
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management