CVE-2024-45712

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*

History

18 Nov 2025, 21:45

Type Values Removed Values Added
CPE cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
First Time Solarwinds
Solarwinds serv-u
References () https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-1_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-1_release_notes.htm - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45712 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45712 - Patch, Vendor Advisory

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) SolarWinds Serv-U es vulnerable a una vulnerabilidad de client-side cross-site scripting (XSS). Esta vulnerabilidad solo puede ejecutarse mediante una cuenta autenticada, en el equipo local y desde la sesión del navegador local. Por lo tanto, el riesgo es muy bajo.

15 Apr 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 09:15

Updated : 2025-11-18 21:45


NVD link : CVE-2024-45712

Mitre link : CVE-2024-45712

CVE.ORG link : CVE-2024-45712


JSON object : View

Products Affected

solarwinds

  • serv-u
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')