Vulnerabilities
Vulnerable Software
Solarwinds:  Security Vulnerabilities
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
CVSS Score
5.4
EPSS Score
0.015
Published
2021-01-15
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
CVSS Score
5.4
EPSS Score
0.013
Published
2021-01-06
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
CVSS Score
5.4
EPSS Score
0.017
Published
2021-01-04
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
CVSS Score
5.4
EPSS Score
0.013
Published
2021-01-04
CVE-2020-10148
Known exploited
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
CVSS Score
9.8
EPSS Score
0.92
Published
2020-12-29
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
CVSS Score
6.5
EPSS Score
0.016
Published
2020-12-21
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
CVSS Score
5.4
EPSS Score
0.017
Published
2020-12-18
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
CVSS Score
5.4
EPSS Score
0.015
Published
2020-12-18
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.
CVSS Score
7.8
EPSS Score
0.004
Published
2020-12-16
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.
CVSS Score
8.4
EPSS Score
0.005
Published
2020-12-16


Contact Us

Shodan ® - All rights reserved