First published: Fri Dec 18 2020(Updated: )
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds | =12.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16955 is classified as a high severity vulnerability due to its potential for XSS attacks.
To fix CVE-2019-16955, update SolarWinds Web Help Desk to the latest version that addresses this vulnerability.
CVE-2019-16955 is associated with cross-site scripting (XSS) attacks via an uploaded SVG document.
CVE-2019-16955 specifically affects SolarWinds Web Help Desk version 12.7.0.
Yes, CVE-2019-16955 can potentially lead to data breaches as it allows attackers to execute malicious scripts in the user's browser.