vendor:
Web Help Desk
by:
loneferret
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Web Help Desk
Affected Version From: 11.0.7
Affected Version To: 11.0.7 (older versions may be affected)
Patch Exists: YES
Related CWE:
CPE: web-help-desk-by-solarwinds
Platforms Tested:
2012
Stored XSS in Web Help Desk by SolarWinds
The Web Help Desk software by SolarWinds is affected by a stored cross-site scripting (XSS) vulnerability. The vulnerability can be exploited by submitting a malicious payload in the Subject and Request Details fields of the client web ticket submit system. Additionally, tickets created automatically via email can also trigger the XSS when viewed. The vulnerability allows an attacker to execute arbitrary script code in the context of the user's browser, potentially leading to session hijacking or the theft of sensitive information.
Mitigation:
Upgrade to a patched version of the software. No further details provided.