CVE-2021-35254: Authenticated Remote Code Execution in WebHelpDesk 12.7.8
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35254?
CVE-2021-35254 is a vulnerability reported in SolarWinds WebHelpDesk where an input that was not sanitized, which has now been removed to prevent misuse.
What software is affected by CVE-2021-35254?
SolarWinds WebHelpDesk versions up to and including 12.7.8 are affected by CVE-2021-35254.
How severe is CVE-2021-35254?
CVE-2021-35254 has a severity rating of 8.8 (high).
How can I fix CVE-2021-35254?
To fix CVE-2021-35254, update SolarWinds WebHelpDesk to version 12.7.8 Hotfix 1 or later.
Where can I find more information about CVE-2021-35254?
You can find more information about CVE-2021-35254 in the SolarWinds support article [Web Help Desk 12.7.8 Hotfix 1 Release Notes](https://support.solarwinds.com/SuccessCenter/s/article/Web-Help-Desk-12-7-8-Hotfix-1-Release-Notes?language=en_US) and the SolarWinds security advisory for [CVE-2021-35254](https://www.solarwinds.com/trust-center/security-advisories/CVE-2021-35254).