Authenticated Remote Code Execution in WebHelpDesk 12.7.8
CVE-2021-35254

8.2HIGH

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
25 March 2022

Summary

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.

Affected Version(s)

WebHelpDesk 12.7.8 and previous versions < 12.7.8 HF 1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.