Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
                
            References
                    | Link | Resource | 
|---|---|
| https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion | Release Notes Vendor Advisory | 
| https://support.solarwinds.com/SuccessCenter/s/ | Vendor Advisory | 
| https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion | Release Notes Vendor Advisory | 
| https://support.solarwinds.com/SuccessCenter/s/ | Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 05:00
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion - Release Notes, Vendor Advisory | |
| References | () https://support.solarwinds.com/SuccessCenter/s/ - Vendor Advisory | 
21 Jan 2022, 14:23
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 3.5
         v3 : 9.0  | 
Information
                Published : 2020-09-17 18:15
Updated : 2024-11-21 05:00
NVD link : CVE-2020-13169
Mitre link : CVE-2020-13169
CVE.ORG link : CVE-2020-13169
JSON object : View
Products Affected
                solarwinds
- orion_platform
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
