Medium severity5.4NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026
CVE-2019-12954
CVE-2019-12954
Description
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- SolarWinds/Network Performance Monitordescription
- Range: 2018
- Range: 12.3
- Range: 1.1.3
- cpe:2.3:a:solarwinds:network_performance_monitor_orion_platform_2018_netpath:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:network_performance_monitor_orion_platform_2018_npm:12.3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.