CVE-2018-19386
SolarWinds Database Performance Analyzer 11.1.457 - Cross-Site Scripting
Record summary
CVE-2018-19386 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSolarWinds Database Performance Analyzer 11.1.457 - Cross-Site ScriptingCVSS 6.1
SolarWinds Database Performance Analyzer 11.1.457 contains a reflected cross-site scripting vulnerability in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking or defacement of the affected application.
Remediation
Apply the latest patch or upgrade to a non-vulnerable version of SolarWinds Database Performance Analyzer.
Source: ProjectDiscovery