Stored HTML Injection Vulnerability in SolarWinds Orion Platform by SolarWinds
CVE-2019-12863

4.8MEDIUM

What is CVE-2019-12863?

The SolarWinds Orion Platform version 2018.4 HF3, including Network Performance Monitor (NPM) 12.4 and NetPath 1.1.4, is susceptible to a Stored HTML Injection vulnerability. This issue arises from improper input validation in the Web Console Settings, allowing administrators to inject malicious HTML content. Successful exploitation could lead to potential user interface manipulation, unauthorized access, or information disclosure. Users and administrators are advised to review their system configurations and implement necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.