CRITICAL🇵🇱 Wersja polska

CVE-2021-27258

CVSS 9.8v3.1pub. 2021-04-14upd. 2024-11-21

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Solarwinds Orion Platform

    APP
    Solarwinds
    2020.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2020-10148CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelnienia w SolarWinds Orion API (RCE)

CVE-2021-25274CRITICAL9.8PL ✓same product

RCE przez niebezpieczną deserializację MSMQ w SolarWinds Orion Platform

CVE-2020-13169CRITICAL9.0PL ✓same product

Stored XSS w SolarWinds Orion Platform — przejęcie konta administratora

CVE-2019-9546CRITICAL9.8PL ✓same product

SolarWinds Orion Platform — privilege escalation przez usługę RabbitMQ

CVE-2022-36963HIGH7.2same product

The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a re...