Vulnerabilities > Solarwinds > Webhelpdesk > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2021-35254 Unspecified vulnerability in Solarwinds Webhelpdesk
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk.
network
low complexity
solarwinds
8.8
2020-04-27 CVE-2019-20002 Improper Neutralization of Formula Elements in a CSV File vulnerability in Solarwinds Webhelpdesk 12.7.1
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
local
low complexity
solarwinds CWE-1236
7.8