SolarWinds Database Performance Analyzer 11.1. 457 - Cross-Site Scripting

Published on
10 Jan 2022
Vulnerability

Description

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the ‘Try Again’ Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

Recommendation

  • Update SolarWinds Database Performance Analyzer to the latest version
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days