The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
https://arcticwolf.com/resources/blog/cve-2024-28988/
https://thehackernews.com/2024/10/cisa-warns-of-active-exploitation-in.html
https://www.theregister.com/2024/08/22/hardcoded_credentials_bug_solarwinds_whd/
https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987
https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2