SolarWinds Web Help Desk
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*, +1 more
An XML External Entity Injection (XXE) vulnerability has been identified in SolarWinds Web Help Desk, specifically in version 12.8.7. This vulnerability could lead to unauthorized information disclosure. It requires valid, low-privilege access, unless the attacker can modify configuration files on the local server.
Exploitation of this vulnerability could result in unauthorized access to sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.