Cross Site Scripting in SolarWinds Serv-U Software
CVE-2021-25179
6.1MEDIUM
Summary
SolarWinds Serv-U prior to version 15.2 is susceptible to an XSS vulnerability that occurs via the manipulation of the HTTP Host header. This security risk can potentially allow an attacker to execute malicious scripts in the context of an affected user's session, leading to unauthorized actions or data exposure. Users are advised to upgrade to a patched version to mitigate these security threats.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved