Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HSolarwinds Orion Platform
APPSolarwinds< 2020.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2020-10148CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelnienia w SolarWinds Orion API (RCE)
CVE-2021-27258CRITICAL9.8PL ✓same product
SolarWinds Orion Platform — nieautoryzowane privilege escalation do Administratora
CVE-2021-25274CRITICAL9.8PL ✓same product
RCE przez niebezpieczną deserializację MSMQ w SolarWinds Orion Platform
CVE-2019-9546CRITICAL9.8PL ✓same product
SolarWinds Orion Platform — privilege escalation przez usługę RabbitMQ
CVE-2022-36963HIGH7.2same product
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a re...