A critical XSS vulnerability was recently disclosed by SolarWinds in its Platform product, a major player in IT management software.
See also: Cisco warns of attacks exploiting ASA vulnerability

The flaw, identified as CVE-2024-45717, allows verified attackers to inject malicious code via a cross-site scripting (XSS) vulnerability. This vulnerability potentially helps malicious actors compromise the integrity and privacy of affected systems.
The XSS vulnerability affects the search and node information sections of the SolarWinds platform user interface.
In addition, SolarWinds experts noted that the flaw requires authentication and user interaction to exploit. Its potential impact is significant, which helps it earn a high severity rating of 7.0 on the Common Vulnerability Scoring System (CVSS).
Affected versions: The vulnerability exists in SolarWinds Platform 2024.4 and all previous versions, putting a wide range of installations at risk.
See also: XSS vulnerability in Bing allows malicious requests
Attack Vector: The CVSS score indicates that the attacker would need to be on the same network segment as the vulnerable system. This somewhat narrows the scope of possible attacks, but does not reduce the severity for organizations with shared network environments.

If successfully exploited, this SolarWinds Platform XSS vulnerability could allow attackers to:
- Steal sensitive information from authenticated users
- Handle the platform's functionality
- Gain unauthorized access to connected systems
The vulnerability was discovered by Frank Lycops from the NATO Cybersecurity Center, highlighting the importance of collective efforts to identify and address cybersecurity threats .
While the SolarWinds Platform XSS vulnerability requires specific conditions to be exploited, its potential consequences are severe enough to warrant immediate attention. Organizations using affected versions of the SolarWinds Platform should prioritize applying the available patch to mitigate the risk of potential attacks exploiting this vulnerability.
See also: RCE & XSS vulnerability in Sonatype Nexus Repository Manager
An XSS vulnerability allows an attacker to inject malicious code into a web page or application, with the intent of executing it in the browser of users visiting the website. The malicious code can be used to steal personal information, track users, or deliver malware. To prevent XSS vulnerabilities, you should take the following security measures:
- Validation and proper extraction of user inputs before they appear on the website.
- Avoid directly inserting scripts from untrusted sources.
- Using secure code development practices and platforms that provide protection against XSS vulnerabilities.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
