SolarWinds Platform Vulnerable to XSS Attack
CVE-2024-45717
4.8MEDIUM
Summary
The SolarWinds Platform is vulnerable to a Cross-Site Scripting (XSS) attack that impacts the search and node information sections of its user interface. This flaw necessitates that users are authenticated and engage with the interface for the exploitation to occur. The XSS vulnerability could allow an attacker to inject malicious scripts into web pages viewed by other users, leading to unauthorized access to sensitive information or manipulation of user sessions.
Affected Version(s)
SolarWinds Platform SolarWinds Platform 2024.4 and prior versions
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Credit
Frank Lycops, NATO Cyber Security Centre