VulnerabilityModified
CVE-2020-13169
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages.
CRITICAL 9.0EPSS 2.21%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- solarwinds/orion platform
- Source
- cve@mitre.org
References
- https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrionRelease Notes, Vendor Advisory
- https://support.solarwinds.com/SuccessCenter/s/Vendor Advisory
- https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrionRelease Notes, Vendor Advisory
- https://support.solarwinds.com/SuccessCenter/s/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.