VYPR
Unrated severityNVD Advisory· Published May 5, 2021· Updated Aug 3, 2024

CVE-2021-25179

CVE-2021-25179

Description

SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SolarWinds Serv-U before 15.2 contains a cross-site scripting vulnerability via the HTTP Host header.

Vulnerability

SolarWinds Serv-U before version 15.2 is affected by a reflected Cross Site Scripting (XSS) vulnerability in the handling of the HTTP Host header [1]. The application does not properly sanitize the Host header value before reflecting it in error responses or logs, allowing an attacker to inject arbitrary HTML or JavaScript. Affected versions are all releases prior to 15.2.

Exploitation

To exploit this vulnerability, an attacker must be able to send a crafted HTTP request to a SolarWinds Serv-U server. The attacker sets the Host header of the request to contain malicious JavaScript code, such as a payload that executes in the context of the victim's browser session. The attack does not require authentication, and no user interaction is needed beyond the victim viewing a page that reflects the malicious header [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser when the Host header is reflected. This could lead to session hijacking, credential theft, or defacement of the web interface, depending on the user's privileges. The impact is limited to the browser session and does not grant direct server access or privileges [1].

Mitigation

SolarWinds addressed this vulnerability in Serv-U version 15.2, released in early 2021. Users should upgrade to version 15.2 or later to eliminate the vulnerability. No workaround is documented in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.