First published: Wed May 05 2021(Updated: )
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Serv-u File Server | <15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25179 has been classified with a CVSS score indicating a moderate severity level.
To fix CVE-2021-25179, update SolarWinds Serv-U to version 15.2 or later.
CVE-2021-25179 is a Cross Site Scripting (XSS) vulnerability that exploits the HTTP Host header.
SolarWinds Serv-U versions prior to 15.2 are affected by CVE-2021-25179.
Yes, if exploited, CVE-2021-25179 could potentially allow attackers to execute malicious scripts in the context of a user's session.