CVE-2022-36965: Stored and DOM XSS in QoE Applications: Orion Platform
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36965?
CVE-2022-36965 is a vulnerability that results from insufficient sanitization of inputs in the QoE application input field, which could lead to stored and DOM-based cross-site scripting (XSS) attacks.
What is the severity of CVE-2022-36965?
CVE-2022-36965 has a severity level of medium, with a CVSS score of 6.1.
How does CVE-2022-36965 affect SolarWinds Platform?
CVE-2022-36965 affects SolarWinds Platform versions up to and including 2022.3.0.
Has CVE-2022-36965 been fixed?
Yes, CVE-2022-36965 has been fixed and released in SolarWinds Platform version 2022.3.0.
Where can I find more information about CVE-2022-36965?
You can find more information about CVE-2022-36965 in the SolarWinds Platform 2022.3.0 release notes and the SolarWinds Trust Center security advisories.