CVE-2020-22428
Description
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SolarWinds Serv-U before 15.1.6 HF3 has a stored XSS vulnerability where an admin can inject JavaScript via a directory name.
Vulnerability
SolarWinds Serv-U versions before 15.1.6 Hotfix 3 are affected by a stored Cross-Site Scripting (XSS) vulnerability. The flaw resides in the directory name field, which is normally entered by an administrator. A JavaScript payload placed as a directory name is not sanitized properly, leading to execution in the context of the application [1].
Exploitation
An attacker must have administrative access to the SolarWinds Serv-U management interface to create or rename a directory to a malicious name containing a JavaScript payload. When other administrators or users view the directory listing, the script executes in their browser. No additional authentication or interaction from the victim is required beyond viewing the affected page [1].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the directory list. This can lead to session hijacking, defacement, or theft of sensitive information within the application context. The attack is limited to the permissions of the affected user [1].
Mitigation
The vulnerability is fixed in SolarWinds Serv-U version 15.1.6 Hotfix 3 and later. Administrators should upgrade to the patched version. As a workaround, restrict administrative access to trusted users only, as the attack requires admin privileges to inject the payload [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- SolarWinds/Serv-Udescription
- Range: <15.1.6 Hotfix 3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-Hotfix-3mitrex_refsource_MISC
- twitter.com/gm4tr1xmitrex_refsource_MISC
- www.linkedin.com/in/gabrielegristinamitrex_refsource_MISC
News mentions
0No linked articles in our index yet.