CVE-2024-52612

SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by a high- privileged account to be exploitable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:solarwinds_platform:*:*:*:*:*:*:*:*

History

25 Feb 2025, 17:29

Type Values Removed Values Added
Summary
  • (es) SolarWinds Platform es vulnerable a una vulnerabilidad de cross-site scripting reflejado. Esto se debió a una depuración insuficiente de los parámetros de entrada. Para poder explotar esta vulnerabilidad, es necesario que una cuenta con privilegios elevados esté autenticada.
First Time Solarwinds
Solarwinds solarwinds Platform
CPE cpe:2.3:a:solarwinds:solarwinds_platform:*:*:*:*:*:*:*:*
References () https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2025-1_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2025-1_release_notes.htm - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/cve-2024-52612 - () https://www.solarwinds.com/trust-center/security-advisories/cve-2024-52612 - Vendor Advisory

11 Feb 2025, 22:15

Type Values Removed Values Added
References
  • () https://www.solarwinds.com/trust-center/security-advisories/cve-2024-52612 -

11 Feb 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 08:15

Updated : 2025-02-25 17:29


NVD link : CVE-2024-52612

Mitre link : CVE-2024-52612

CVE.ORG link : CVE-2024-52612


JSON object : View

Products Affected

solarwinds

  • solarwinds_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')