Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-26400

Опубликовано: 29 июл. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
Версия до 12.8.7 (исключая)

EPSS

Процентиль: 1%
0.00008
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.3
github
6 месяцев назад

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

EPSS

Процентиль: 1%
0.00008
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-611