Access Restriction Bypass via referrer spoof was...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2024
Description
Published by the National Vulnerability Database
Aug 26, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 3, 2024
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the “Web Help Desk Getting Started Wizard”, especially the admin account creationpage, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
References