Описание
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
Ссылки
- Release NotesVendor Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2020.2.1 (исключая)
cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*
EPSS
Процентиль: 81%
0.01534
Низкий
9 Critical
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
EPSS
Процентиль: 81%
0.01534
Низкий
9 Critical
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79