CVE-2019-16961: XSS
Published Jan 15, 2021
·Updated
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
Affected Software
1 affected component
SolarWinds Web Help Desk=12.7.0
Event History
Jan 15, 2021
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16961?
CVE-2019-16961 is a vulnerability in SolarWinds Web Help Desk 12.7.0 that allows for cross-site scripting (XSS) attacks through a Schedule Name field.
2
How severe is CVE-2019-16961?
CVE-2019-16961 has a severity rating of 5.4 (medium).
3
How can I be affected by CVE-2019-16961?
You can be affected by CVE-2019-16961 if you are using SolarWinds Web Help Desk version 12.7.0.
4
How can I fix CVE-2019-16961?
To fix CVE-2019-16961, you should update SolarWinds Web Help Desk to a version that includes a patch for this vulnerability.
5
Where can I find more information about CVE-2019-16961?
You can find more information about CVE-2019-16961 on the SolarWinds support website and the EsecForte website.