A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21882 A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
Fixes

Solution

SolarWinds recommends installing 2020.2.6 Hotfix 1 for the Orion Platform as soon as it becomes available. All customers should implement all the recommendations from the Orion Secure Configuration Guide.


Workaround

If you are unable to upgrade immediately. See SolarWinds Knowledgebase Article Below: https://support.solarwinds.com/SuccessCenter/s/article/Mitigate-the-Stored-XSS-in-Maps-text-box-hyperlink-vulnerability-CVE-2021-35239?language=en_US

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00175}

epss

{'score': 0.00157}


cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2024-08-04T00:33:51.271Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-31T16:15:07.807

Modified: 2024-11-21T06:12:07.843

Link: CVE-2021-35239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.