CVE-2019-20002 describes a Formula Injection vulnerability in SolarWinds WebHelpDesk 12.7.1. A low-privileged user can embed malicious formulas in the Subject field of a help request, which are then mishandled during a TSV export by an administrator. This vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk. It requires user interaction (UI:R) from an administrator to trigger the exploit, but successful exploitation could lead to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.7.1CPE matchmatch criteria | cpe:2.3:a:solarwinds:webhelpdesk:12.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.