CVE-2024-45717

HIGH

SolarWinds Platform < 2024.4.1 - Authenticated Stored Cross-Site Scripting in Search and Node Information UI

Title source: llm
STIX 2.1

Description

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction.

Scores

CVSS v3 7.0
EPSS 0.0032
EPSS Percentile 55.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
solarwinds/solarwinds_platform < 2024.4.1
Published Dec 04, 2024
Tracked Since Feb 18, 2026