Required CVE Record Information
Description
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
CWE 1 Total
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.1 | HIGH | 3.1 | CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L |
Credits
- Jakub Brzozowski, Kamil Falkiewicz, Szymon Jacek with STM Cyber finder
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-29004 vendor-advisoryx_transferred
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2024-2_release_notes.htm release-notesx_transferred