CVE-2019-16959: Medium severity solarwinds vulnerability
Published Dec 21, 2020
·Updated
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Affected Software
1 affected component
SolarWinds WebHelpDesk=12.7.0
Event History
Dec 21, 2020
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16959?
CVE-2019-16959 has a medium severity level due to its risk of CSV injection attacks.
2
How do I fix CVE-2019-16959?
To mitigate CVE-2019-16959, users should sanitize user input to prevent the execution of unexpected formulas.
3
What is CSV Injection in the context of CVE-2019-16959?
CSV Injection, also known as formula injection, allows malicious users to inject harmful formulas into CSV files.
4
Which versions of SolarWinds Web Help Desk are affected by CVE-2019-16959?
CVE-2019-16959 specifically affects SolarWinds Web Help Desk version 12.7.0.
5
What are the potential impacts of CVE-2019-16959?
The potential impacts of CVE-2019-16959 include data manipulation and unauthorized access through crafted CSV files.