XML External Entity Injection in SolarWinds Web Help Desk
CVE-2025-26400
5.3MEDIUM
What is CVE-2025-26400?
The SolarWinds Web Help Desk has been found to have an XML External Entity Injection vulnerability that could potentially lead to unauthorized information disclosure. Attackers with valid, low-privileged access may exploit this issue unless they gain access to the local server to alter configuration files. Proper safeguards and configurations are essential to mitigate this risk. Organizations using affected versions should review their security measures and apply the necessary updates.
Affected Version(s)
Web Help Desk 12.8.6 and previous versions
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
DieuLink, Nhiephon, and chung96vn from GCSC Vietnam