ZeroHour

CVE-2018-19386

PoC ×2
CVSS 3.0
6.1 medium
EPSS
9%p95
Published
()
Modified
Description

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

Vendors
solarwinds
Products
database performance analyzer
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.