CVE-2024-45715: SolarWinds Platform Edit Function Cross-Site Scripting Vulnerability
Published Oct 16, 2024
·Updated
The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2024.4
Remediation
Information
SolarWinds recommends that customers upgrade to SolarWinds Platform 2024.4 as soon as it becomes available.
Event History
Oct 16, 2024
CVE Published
via MITRE·07:17 AM
Data Sourced
via MITRE·07:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45715?
CVE-2024-45715 is considered to be of medium severity due to its potential for exploitation via Cross-Site Scripting.
2
How do I fix CVE-2024-45715?
To fix CVE-2024-45715, update the SolarWinds Platform to version 2024.4 or later.
3
What types of attacks can CVE-2024-45715 enable?
CVE-2024-45715 can enable attackers to execute arbitrary scripts in the user's browser session.
4
Which versions of SolarWinds Platform are affected by CVE-2024-45715?
Versions of SolarWinds Platform prior to 2024.4 are affected by CVE-2024-45715.
5
What functions in the SolarWinds Platform are impacted by CVE-2024-45715?
CVE-2024-45715 affects the edit functionality of existing elements within the SolarWinds Platform.