SolarWinds Orion Platform
cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*
- 2019.2 HF1
A stored client-side template injection vulnerability has been identified in the SolarWinds Orion Platform version 2019.2 HF1. This vulnerability allows an attacker to inject an Angular expression, escaping the Angular sandbox to achieve stored cross-site scripting. The consequence of this vulnerability could lead to privilege escalation.
Exploitation of this vulnerability could result in stored cross-site scripting, allowing injected scripts to be executed in the context of the user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.