Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32076

Опубликовано: 26 авг. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
Версия до 12.7.2 (включая)

EPSS

Процентиль: 65%
0.00485
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-290
CWE-290

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the “Web Help Desk Getting Started Wizard”, especially the admin account creationpage, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

EPSS

Процентиль: 65%
0.00485
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-290
CWE-290