QID 376426
Date Published: 2022-02-28
QID 376426: SolarWinds Orion Platform Cross-Site Scripting (XSS) Vulnerability
SolarWinds Orion is an IT performance monitoring platform
SolarWinds Orion is affected with Cross-Site Scripting vulnerability
Affected Versions:
SolarWinds Orion Platform prior to 2020.2.1
QID Detection Logic (Authenticated):
The QID extracts Solarwinds Orion installation path from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.BusinessLayer.dll" with patched versions
When registry keys are not accessible, we skip the path extracting, directly check file versions of "%ProgramFiles%\SolarWinds\Orion\SolarWinds.Orion.Core.BusinessLayer.dll" and "%ProgramFiles(x86)%\SolarWinds\Orion\SolarWinds.Orion.Core.BusinessLayer.dll".
Successful exploitation may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
Customers are advised to refer to Orion Platform 2020.2.1 Release Notes
- orion_platform_2020-2-1_release_notes -
documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-1_release_notes.htm#NewFeaturesOrion
CVEs related to QID 376426
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Orion Platform 2020.2.1 |
|