Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

No history.

cve-icon MITRE


Assigner: SolarWinds

Published: 2021-08-20T00:00:00

Updated: 2024-08-03T23:17:29.330Z

Reserved: 2021-05-06T00:00:00

Link: CVE-2021-32076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-26T15:15:06.993

Modified: 2024-01-25T21:34:02.087

Link: CVE-2021-32076

cve-icon Redhat

No data.