Record summary

CVE-2018-19386 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSolarWinds Database Performance Analyzer 11.1.457 - Cross-Site ScriptingCVSS 6.1

SolarWinds Database Performance Analyzer 11.1.457 contains a reflected cross-site scripting vulnerability in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking or defacement of the affected application.

Remediation

Apply the latest patch or upgrade to a non-vulnerable version of SolarWinds Database Performance Analyzer.

WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2018solarwindsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:solarwinds:database_performance_analyzer:11.1.457:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3