CVE-2021-25179: XSS
Published May 5, 2021
·Updated
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
Affected Software
1 affected component
SolarWinds Serv-u File Server<15.2
Event History
May 5, 2021
CVE Published
via MITRE·02:40 AM
Data Sourced
via MITRE·02:40 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25179?
CVE-2021-25179 has been classified with a CVSS score indicating a moderate severity level.
2
How do I fix CVE-2021-25179?
To fix CVE-2021-25179, update SolarWinds Serv-U to version 15.2 or later.
3
What type of vulnerability is CVE-2021-25179?
CVE-2021-25179 is a Cross Site Scripting (XSS) vulnerability that exploits the HTTP Host header.
4
Which versions of SolarWinds Serv-U are affected by CVE-2021-25179?
SolarWinds Serv-U versions prior to 15.2 are affected by CVE-2021-25179.
5
Can CVE-2021-25179 lead to unauthorized access?
Yes, if exploited, CVE-2021-25179 could potentially allow attackers to execute malicious scripts in the context of a user's session.