SolarWinds Web Help Desk XML External Entity Injection Vulnerability

Vulnerability

An XML External Entity Injection (XXE) vulnerability has been identified in SolarWinds Web Help Desk, specifically in version 12.8.7. This vulnerability could lead to unauthorized information disclosure. It requires valid, low-privilege access, unless the attacker can modify configuration files on the local server.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information.

Added: Jul 29, 2025, 9:24 AM
Updated: Jul 29, 2025, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.