Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
References
Link | Resource |
---|---|
https://gist.github.com/alert3/f8d33412ab0c671d3cac6a50b132a894 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-06-24 07:15
Updated : 2020-07-06 19:03
NVD link : CVE-2020-14007
Mitre link : CVE-2020-14007
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
solarwinds
- orion_network_performance_monitor
- orion_web_performance_monitor