PoC Index

CVE-2018-19386

MEDIUM 6.1EPSS 9.0%

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
9.04% chance of exploitation in the next 30 days, 95th percentile
Nuclei
medium · CWE-79
Published
2019-08-14
Updated
2024-08-05

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related