CVE-2019-16955: XSS
Published Dec 18, 2020
·Updated
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
Affected Software
1 affected component
SolarWinds WebHelpDesk=12.7.0
Event History
Dec 18, 2020
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16955?
CVE-2019-16955 is classified as a high severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2019-16955?
To fix CVE-2019-16955, update SolarWinds Web Help Desk to the latest version that addresses this vulnerability.
3
What type of attack is associated with CVE-2019-16955?
CVE-2019-16955 is associated with cross-site scripting (XSS) attacks via an uploaded SVG document.
4
What versions of SolarWinds are affected by CVE-2019-16955?
CVE-2019-16955 specifically affects SolarWinds Web Help Desk version 12.7.0.
5
Can CVE-2019-16955 lead to data breaches?
Yes, CVE-2019-16955 can potentially lead to data breaches as it allows attackers to execute malicious scripts in the user's browser.