Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lidor Levy

#33830of 56,333
7.9Total CVSS
Vulnerabilities · 1
PT-2024-7954
7.9
2024-04-18
Solarwinds · Solarwinds Platform · CVE-2024-29000
**Name of the Vulnerable Software and Affected Versions** SolarWinds Platform versions prior to 2024.1 **Description** The issue is related to a reflected cross-site scripting vulnerability in the web console of the SolarWinds Platform. This vulnerability requires a high-privileged user and user interaction to be exploited. It may allow a remote attacker to conduct cross-site scripting attacks due to inadequate protection of the web page structure. **Recommendations** For versions prior to 2024.1, upgrade the affected components immediately to mitigate the risks. As a temporary workaround, consider restricting access to the web console to minimize the risk of exploitation. Avoid using the web console until the issue is resolved.