Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.5epss 0.6%
probabilidad de explotación
0.6%top 54% de las CVE
explotación observada
noninguna fuente lo reporta
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
SolarWinds · SolarWinds