CVE-2012-2602

SolarWinds Orion NPM <10.3.1 - CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2602. PoCs published by muts.

AI-analyzed exploit summary This JavaScript exploit demonstrates a persistent XSS vulnerability in SolarWinds Orion NPM 10.2.2, allowing an attacker to inject malicious scripts via SNMP fields (syslocation, syscontact, sysName) and perform CSRF attacks to create admin accounts.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

Exploits (1)

exploitdb WORKING POC VERIFIED
by muts · javascriptwebappswindows
https://www.exploit-db.com/exploits/20011

This JavaScript exploit demonstrates a persistent XSS vulnerability in SolarWinds Orion NPM 10.2.2, allowing an attacker to inject malicious scripts via SNMP fields (syslocation, syscontact, sysName) and perform CSRF attacks to create admin accounts.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: SolarWinds Orion Network Performance Monitor 10.2.2
No auth needed
Prerequisites: Access to modify SNMP fields on a scanned system · Victim must access the SolarWinds Orion interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/174119
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50004
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54624
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/20011
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/84116

Scores

EPSS 0.0598
EPSS Percentile 92.4%

Details

CWE
CWE-352
Status published
Products (2)
solarwinds/orion_network_performance_monitor 10.1.13.0
solarwinds/orion_network_performance_monitor < 10.2.2
Published Aug 12, 2012
Tracked Since Feb 18, 2026