SolarWinds has fixed a critical vulnerability in its Web Help Desk software, which could allow attackers to log in to vulnerable systems with hardcoded credentials.

Web Help Desk (WHD) is a popular software , used by many government agencies, large corporations, and healthcare and education organizations.
See also: GitHub: GHES vulnerability allows authentication bypass
The vulnerability is tracked as CVE-2024-28987 and was patched on Wednesday (Web Help Desk 12.8.3 Hotfix 2). Unauthorized attackers can exploit it to gain access to internal functions and modify data on targeted devices.
SolarWinds has not disclosed whether CVE-2024-28987 has been used in attacks.
See also: LiteSpeed Cache vulnerability puts millions of WordPress sites at risk
The company provides detailed instructions on how to install and remove the hotfix, warning administrators to upgrade vulnerable servers to Web Help Desk 12.8.3.1813 or 12.8.3 HF1 before deploying the hotfix. It also recommends backing up all source files before installing the update.

It is worth noting that the SolarWinds update itself also includes another Web Help Desk vulnerability (CVE-2024-28986), which was addressed with another hotfix on August 14 and was flagged by CISA as a vulnerability used in attacks.
See also: Google Chrome: Fix for new zero-day vulnerability
These Web Help Desk vulnerabilities highlight the importance of proactive cybersecurity practices and responsible disclosure in today’s digital landscape. Organizations should prioritize updating software , implementing additional security , and regularly assessing their systems for potential vulnerabilities. By following these steps, a more secure and resilient digital world can be created. So stay vigilant and prioritize security in all aspects of your operations!
Source: www.bleepingcomputer.com
