Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-40545

Опубликовано: 18 нояб. 2025
Источник: nvd
CVSS3: 4.8
CVSS3: 4.4
EPSS Низкий

Описание

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*
Версия до 2025.4.1 (исключая)

EPSS

Процентиль: 7%
0.00027
Низкий

4.8 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.8
github
3 месяца назад

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.

EPSS

Процентиль: 7%
0.00027
Низкий

4.8 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-601