CVE-2021-35228
Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
21 oct 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
SolarWinds · SolarWinds¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →