CVE-2019-16960: XSS
Published Jan 4, 2021
·Updated
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
Affected Software
1 affected component
SolarWinds Web Help Desk=12.7.0
Event History
Jan 4, 2021
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for SolarWinds Web Help Desk?
The vulnerability ID for SolarWinds Web Help Desk is CVE-2019-16960.
2
What is the severity of CVE-2019-16960?
CVE-2019-16960 has a severity value of 5.4, which is considered medium.
3
How does SolarWinds Web Help Desk 12.7.0 allow XSS?
SolarWinds Web Help Desk 12.7.0 allows XSS through a CSV template file with a crafted Location Name field.
4
Which version of SolarWinds Web Help Desk is affected by CVE-2019-16960?
CVE-2019-16960 affects SolarWinds Web Help Desk version 12.7.0.
5
How can I fix the XSS vulnerability in SolarWinds Web Help Desk 12.7.0?
To fix the XSS vulnerability in SolarWinds Web Help Desk 12.7.0, it is recommended to update to a patched version provided by SolarWinds.