This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21871 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. |
Fixes
Solution
SolarWinds recommends upgrading to the latest version of the DPA as soon as it becomes available.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-16T23:56:04.954Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35228
No data.
Status : Modified
Published: 2021-10-21T18:15:10.217
Modified: 2024-11-21T06:12:06.310
Link: CVE-2021-35228
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD