Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2021-18937 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback. |
Fixes
Solution
SolarWinds has released version 12.7.6 and it is suggested to upgrade as soon as possible.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-17T01:00:44.305Z
Reserved: 2021-05-06T00:00:00
Link: CVE-2021-32076

No data.

Status : Modified
Published: 2021-08-26T15:15:06.993
Modified: 2024-11-21T06:06:48.670
Link: CVE-2021-32076

No data.

No data.