CVE-2021-35228

MEDIUM

Solarwinds Database Performance Analyzer - Reflective Cross-Site Scripting

Title source: llm
STIX 2.1

Description

This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.

Scores

CVSS v3 5.5
EPSS 0.0125
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-79
Status published
Products (1)
solarwinds/database_performance_analyzer 2021.3.7388
Published Oct 21, 2021
Tracked Since Feb 18, 2026