PT-2024-7954 · Solarwinds · Solarwinds Platform

Lidor Levy

·

Published

2024-04-18

·

Updated

2024-07-11

·

CVE-2024-29000

CVSS v3.1

7.9

High

VectorAV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Platform versions prior to 2024.1
Description The issue is related to a reflected cross-site scripting vulnerability in the web console of the SolarWinds Platform. This vulnerability requires a high-privileged user and user interaction to be exploited. It may allow a remote attacker to conduct cross-site scripting attacks due to inadequate protection of the web page structure.
Recommendations For versions prior to 2024.1, upgrade the affected components immediately to mitigate the risks. As a temporary workaround, consider restricting access to the web console to minimize the risk of exploitation. Avoid using the web console until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-09467
CVE-2024-29000

Affected Products

Solarwinds Platform