CVE-2024-28987

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.


We have discovered 31 live websites that are affected by CVE-2024-28987.

Run a Free Instant Scan




Affected Software

Product  Web Help Desk
Category Help desk
Vulnerable Domains31 live websites (65% of Web Help Desk install base)
Vulnerable Versions
  • from 0 through 12.8.3
Vulnerable Versions Count6 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-798 Use of Hard-coded Credentials



Details

  • Published - Aug 21, 2024
  • Updated - Oct 21, 2025

Credits

  • Zach Hanley (finder)

Website Distribution by Country

Number of websites using CVE-2024-28987
United States23 websites



GB2 websites
Australia1 websites
Canada1 websites
Spain1 websites
Mexico1 websites
Tanzania1 websites

Website Distribution by TLD

Number of websites using CVE-2024-28987
.org10 websites
.com7 websites
.edu3 websites
.co.uk2 websites
.ca1 websites
.com.au1 websites
.net1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-28987

Top websites that are affected by CVE-2024-28987. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.vg United States**,***,***
*******.******.com United States**,***,***
*******.**********.edu United States**,***,***
***.*********.org **,***,***
*******.****.***.au Australia**,***,***
******.*******.gov United States**,***,***
*************.****.mx Mexico**,***,***
********.************.com United States**,***,***
***********.************.org United States**,***,***
********.**********.org United States**,***,***
See full domain list

FAQ

CVE-2024-28987 is Use of Hard-coded Credentials in Web Help Desk
A total of 31 websites have been identified as vulnerable to CVE-2024-28987, based on global website indexing conducted by WebTechSurvey.
The Web Help Desk is affected by the CVE-2024-28987 vulnerability.
Web Help Desk versions up to and including 12.8.3 are vulnerable to CVE-2024-28987.