Authenticated Remote Code Execution in WebHelpDesk 12.7.8
CVE-2021-35254

8.2HIGH

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
25 March 2022

What is CVE-2021-35254?

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.

Affected Version(s)

WebHelpDesk 12.7.8 and previous versions < 12.7.8 HF 1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.