CVE-2021-32076: Access Restriction bypass vulnerability via referrer spoof - Business Logic Bypass
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32076?
The severity of CVE-2021-32076 is medium with a severity value of 5.3.
How does CVE-2021-32076 affect SolarWinds Web Help Desk?
CVE-2021-32076 affects SolarWinds Web Help Desk version 12.7.2.
What is the vulnerability description of CVE-2021-32076?
CVE-2021-32076 is an access restriction bypass vulnerability via referrer spoof in SolarWinds Web Help Desk version 12.7.2.
What can an attacker do with CVE-2021-32076?
An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP requests.
Are there any references available for CVE-2021-32076?
Yes, please refer to the following links for more information: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/208278), [Link 2](https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076)