PT-2024-7954 · Solarwinds · Solarwinds Platform
Lidor Levy
·
Published
2024-04-18
·
Updated
2024-07-11
·
CVE-2024-29000
CVSS v3.1
7.9
High
| Vector | AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds Platform versions prior to 2024.1
Description
The issue is related to a reflected cross-site scripting vulnerability in the web console of the SolarWinds Platform. This vulnerability requires a high-privileged user and user interaction to be exploited. It may allow a remote attacker to conduct cross-site scripting attacks due to inadequate protection of the web page structure.
Recommendations
For versions prior to 2024.1, upgrade the affected components immediately to mitigate the risks. As a temporary workaround, consider restricting access to the web console to minimize the risk of exploitation. Avoid using the web console until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Platform