ZDI-25-104: SolarWinds Platform TestWebsiteUrl Server-Side Request Forgery Information Disclosure Vulnerability
Published Mar 3, 2025
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Platform. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-52606.
Affected Software
1 affected component
SolarWinds Platform
Event History
Mar 3, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-104?
The severity of ZDI-25-104 is rated at 7.1 on the CVSS scale.
2
What does ZDI-25-104 affect?
ZDI-25-104 affects installations of the SolarWinds Platform.
3
Can ZDI-25-104 be exploited without authentication?
No, authentication is required to exploit the vulnerability ZDI-25-104.
4
What type of vulnerability is ZDI-25-104?
ZDI-25-104 is a vulnerability that allows remote attackers to disclose sensitive information.
5
How do I fix ZDI-25-104?
To fix ZDI-25-104, ensure that your SolarWinds Platform is updated to the latest version that patches this vulnerability.