CVE-2024-28987

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
21/08/2024
Last modified:
27/10/2025

Description

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* 12.8.3 (excluding)
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix1:*:*:*:*:*:*