CVE-2010-4828: XSS
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName parameter to CustomChart.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4828?
CVE-2010-4828 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute malicious scripts.
How do I fix CVE-2010-4828?
To fix CVE-2010-4828, ensure you apply the latest security patches for SolarWinds Orion Network Performance Monitor version 10.1.
What are the affected components in CVE-2010-4828?
The affected components include MapView.aspx, NodeDetails.aspx, and InterfaceDetails.aspx within SolarWinds Orion Network Performance Monitor 10.1.
Can CVE-2010-4828 lead to data theft?
Yes, CVE-2010-4828 can lead to data theft by allowing attackers to inject scripts that may steal session cookies or sensitive information from users.
Who is impacted by CVE-2010-4828?
Organizations using SolarWinds Orion Network Performance Monitor version 10.1 are impacted by CVE-2010-4828.