
Cloud Vulnerability DB
A community-led vulnerabilities database
SolarWinds Web Help Desk 12.7.0 contains an HTML injection vulnerability (CVE-2019-16954) that allows HTML injection via a Comment in a Help Request ticket. The vulnerability was discovered by Abhinav Khanna from eSec Forte Technologies and was reported to MITRE (MITRE CVE, NVD).
The vulnerability is classified as a type of injection vulnerability where a user can control an input point and inject arbitrary HTML code into a vulnerable web page. The CVSS v3.1 base score is 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerability is related to improper neutralization of input during web page generation (CWE-79) (NVD).
The vulnerability can lead to disclosure of user's session cookies and modification of page content seen by victims. It can potentially be chained with CSRF attacks to increase the impact (eSec Forte).
The vulnerability exists in the Comment functionality of Help Request tickets. An authenticated user with access to the ticketing system can exploit this by submitting HTML code in the Comment field of a ticket. The exploitation has been confirmed in version 12.7.0 of the Web Help Desk software (eSec Forte).
The primary recommendation is to filter metacharacters from user input. Organizations should ensure they are not running the vulnerable version (12.7.0) of SolarWinds Web Help Desk and update to a patched version (SolarWinds Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."