CVE-2019-12863

MEDIUM

SolarWinds Orion Platform 2018.4 HF3 - Stored Cross-Site Scripting via Web Console Settings Screen

Title source: llm
STIX 2.1

Description

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.

Scores

CVSS v3 4.8
EPSS 0.0186
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
solarwinds/netpath 1.1.4
solarwinds/network_performance_monitor 12.4
solarwinds/orion_platform 2018.4 hotfix3
Published Feb 25, 2020
Tracked Since Feb 18, 2026