User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21881 User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
Fixes

Solution

SolarWinds recommends installing 2020.2.6 Hotfix 1 for the Orion Platform as soon as it becomes available. All customers should implement all the recommendations from the Orion Secure Configuration Guide.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2024-08-04T00:33:51.272Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-01T12:15:07.607

Modified: 2024-11-21T06:12:07.683

Link: CVE-2021-35238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.