CRITICAL🇵🇱 Wersja polska

CVE-2020-13169

CVSS 9.0v3.1pub. 2020-09-17upd. 2024-11-21

Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Solarwinds Orion Platform

    APP
    Solarwinds
    < 2020.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-10148CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelnienia w SolarWinds Orion API (RCE)

CVE-2021-27258CRITICAL9.8PL ✓same product

SolarWinds Orion Platform — nieautoryzowane privilege escalation do Administratora

CVE-2021-25274CRITICAL9.8PL ✓same product

RCE przez niebezpieczną deserializację MSMQ w SolarWinds Orion Platform

CVE-2019-9546CRITICAL9.8PL ✓same product

SolarWinds Orion Platform — privilege escalation przez usługę RabbitMQ

CVE-2022-36963HIGH7.2same product

The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a re...