SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
References
| Link | Resource |
|---|---|
| https://www.solarwinds.com/free-tools/free-help-desk-software | Product |
| https://support.solarwinds.com/SuccessCenter/s/ | Product |
| https://www.esecforte.com/formula-injection-vulnerability-india-in-solarwinds-web-help-desk/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-12-21 16:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-16959
Mitre link : CVE-2019-16959
JSON object : View
Products Affected
solarwinds
- webhelpdesk
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
