Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
References
Link | Resource |
---|---|
https://gist.github.com/alert3/f8d33412ab0c671d3cac6a50b132a894 | Exploit Third Party Advisory |
https://gist.github.com/alert3/f8d33412ab0c671d3cac6a50b132a894 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/alert3/f8d33412ab0c671d3cac6a50b132a894 - Exploit, Third Party Advisory |
Information
Published : 2020-06-24 14:15
Updated : 2024-11-21 05:02
NVD link : CVE-2020-14007
Mitre link : CVE-2020-14007
CVE.ORG link : CVE-2020-14007
JSON object : View
Products Affected
solarwinds
- orion_network_performance_monitor
- orion_web_performance_monitor
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')