Reflected Cross Site Scripting affecting SolarWinds: DPA 2021.3.7388
(CVE-2021-35228)
Summary
The vulnerability occurred due to missing input sanitization for one of the output fields extracted from headers on a specific section of a page. An attacker would need to perform a “Man in the Middle” attack to change a header for a remote victim. causing a reflective cross site scripting attack affecting SolarWinds DPA v2021.3.7388.
Affected Products
- DPA 2021.3.7388
Fixed Software Release
Acknowledgments
- Faris Roslin
Advisory Details
Severity
5.5 Medium
Advisory ID
First Published
10/19/2021