First published: Tue Apr 15 2025(Updated: )
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rhinosoft Serv-U |
SolarWinds recommends that customers upgrade to SolarWinds Serv-U 15.5.1 as soon as it becomes available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-45712 is considered very low due to its requirement for authenticated access on the local machine.
To fix CVE-2024-45712, ensure that you apply the latest patches and updates from SolarWinds for Serv-U.
CVE-2024-45712 affects users of SolarWinds Serv-U who have authenticated accounts on the local machine.
CVE-2024-45712 is a client-side cross-site scripting (XSS) vulnerability.
CVE-2024-45712 cannot be exploited remotely as it requires an authenticated account on the local machine.