Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2021-35244

Disclosure Date: December 20, 2021 (last updated October 07, 2023)
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
Attacker Value
Unknown

CVE-2021-35238

Disclosure Date: September 01, 2021 (last updated November 28, 2024)
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
Attacker Value
Unknown

CVE-2021-35212

Disclosure Date: August 31, 2021 (last updated November 28, 2024)
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
Attacker Value
Unknown

CVE-2021-35239

Disclosure Date: August 31, 2021 (last updated November 28, 2024)
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
Attacker Value
Unknown

CVE-2021-27277

Disclosure Date: April 22, 2021 (last updated November 28, 2024)
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the OneTimeJobSchedulerEventsService WCF service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11955.
Attacker Value
Unknown

CVE-2021-27258

Disclosure Date: April 14, 2021 (last updated November 28, 2024)
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.
Attacker Value
Unknown

CVE-2020-27870

Disclosure Date: February 10, 2021 (last updated November 28, 2024)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11917.
Attacker Value
Unknown

CVE-2020-27871

Disclosure Date: February 10, 2021 (last updated November 28, 2024)
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within VulnerabilitySettings.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11902.