Medium severity6.1NVD Advisory· Published Aug 14, 2019· Updated Jun 17, 2026
CVE-2018-19386
CVE-2018-19386
Description
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
Affected products
3- SolarWinds/Database Performance Analyzerdescription
11.1.457+ 1 more
- (no CPE)range: 11.1.457
- cpe:2.3:a:solarwinds:database_performance_analyzer:11.1.457:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- i.imgur.com/Y7t2AD6.pngnvdExploitThird Party Advisory
- medium.com/greenwolf-security/reflected-xss-in-solarwinds-database-performance-analyzer-988bd7a5cd5nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.