Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
References
Link | Resource |
---|---|
https://support.solarwinds.com/SuccessCenter/s/ | Vendor Advisory |
https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion | Release Notes Vendor Advisory |
Configurations
Information
Published : 2020-09-17 11:15
Updated : 2022-01-21 06:23
NVD link : CVE-2020-13169
Mitre link : CVE-2020-13169
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
solarwinds
- orion_platform