First published: Tue Dec 01 2020(Updated: )
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Web Help Desk | =12.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16958 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2019-16958, update to the latest version of SolarWinds Web Help Desk that addresses this XSS vulnerability.
CVE-2019-16958 specifically affects SolarWinds Web Help Desk version 12.7.0.
CVE-2019-16958 allows attackers to execute arbitrary web scripts or HTML through cross-site scripting in the Location Name field.
No, CVE-2019-16958 can be exploited without authentication, making it a significant risk to users.