Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
References
Link | Resource |
---|---|
https://medium.com/@ayaan.saikia91/formula-injection-vulnerability-on-solarwinds-webhelpdesk-12-7-1-37569cd4cdc1 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-04-27 08:15
Updated : 2021-07-21 04:39
NVD link : CVE-2019-20002
Mitre link : CVE-2019-20002
JSON object : View
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Products Affected
solarwinds
- webhelpdesk