{"api_version":"1","generated_at":"2026-07-24T19:52:42+00:00","cve":"CVE-2020-13169","urls":{"html":"https://cve.report/CVE-2020-13169","api":"https://cve.report/api/cve/CVE-2020-13169.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-13169","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-13169"},"summary":{"title":"CVE-2020-13169","description":"Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-09-17 18:15:00","updated_at":"2022-01-21 14:23:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://support.solarwinds.com/SuccessCenter/s/","name":"https://support.solarwinds.com/SuccessCenter/s/","refsource":"MISC","tags":["Vendor Advisory"],"title":"SolarWinds Product Support | Success Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion","name":"https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"Orion Platform 2020.2.1 Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-13169","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13169","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"13169","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solarwinds","cpe5":"orion_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13169","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solarwinds","cpe5":"orion_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-13169","qid":"376426","title":"SolarWinds Orion Platform Cross-Site Scripting (XSS) Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-13169","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://support.solarwinds.com/SuccessCenter/s/","refsource":"MISC","name":"https://support.solarwinds.com/SuccessCenter/s/"},{"refsource":"CONFIRM","name":"https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion","url":"https://documentation.solarwinds.com/en/Success_Center/orionplatform/Content/Release_Notes/Orion_Platform_2020-2-1_release_notes.htm#NewFeaturesOrion"}]}},"nvd":{"publishedDate":"2020-09-17 18:15:00","lastModifiedDate":"2022-01-21 14:23:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL"},"exploitabilityScore":2.3,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*","versionEndExcluding":"2020.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"13169","Ordinal":"174348","Title":"CVE-2020-13169","CVE":"CVE-2020-13169","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"13169","Ordinal":"1","NoteData":"Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).","Type":"Description","Title":null},{"CveYear":"2020","CveId":"13169","Ordinal":"2","NoteData":"2020-09-17","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"13169","Ordinal":"3","NoteData":"2020-09-17","Type":"Other","Title":"Modified"}]}}}