SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* |
Wed, 16 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low. | |
| Title | SolarWinds Serv-U Client-Side Cross-Site Scripting Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published: 2025-04-15T08:39:23.242Z
Updated: 2025-04-15T13:58:41.012Z
Reserved: 2024-09-05T08:28:03.887Z
Link: CVE-2024-45712
Updated: 2025-04-15T13:58:36.395Z
Status : Analyzed
Published: 2025-04-15T09:15:13.293
Modified: 2025-11-18T21:45:38.497
Link: CVE-2024-45712
No data.