Description
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- SolarWinds / SolarWinds Observability Self-HostedSolarWinds Observability Self-Hosted 2025.4 and prior versions – SolarWinds Observability Self-Hosted 2025.4 and prior versions