CVE-2021-32604
Description
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SolarWinds Serv-U before 15.2.3 contains a stored XSS vulnerability in Share/IncomingWizard.htm via the SenderEmail parameter.
Vulnerability
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, leading to a stored cross-site scripting (XSS) vulnerability. The code path is reachable when a user interacts with the share file wizard functionality, and the parameter is not properly sanitized before being stored or rendered.
Exploitation
An attacker needs to supply a malicious payload in the SenderEmail parameter. This can be done by crafting a specially crafted URL or form submission. When the affected page processes the parameter, the injected script is stored and later executed in the context of other users' browsers who view the share wizard page. No authentication is explicitly required to trigger the stored XSS, as the vulnerable component may be accessible to unauthenticated users.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session token theft, account impersonation, defacement, or redirection to malicious sites. The attack results in information disclosure and potential compromise of the user's session within the SolarWinds Serv-U interface.
Mitigation
The vulnerability is fixed in SolarWinds Serv-U version 15.2.3. Users should upgrade to this version or later. No workarounds have been disclosed for versions prior to the fix. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- SolarWinds/Serv-Udescription
- Range: <15.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-2-3_release_notes.htmmitrex_refsource_MISC
- www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/solarwinds-serv-u-1523-share-url-xss-cve-2021-32604/mitrex_refsource_MISC
- www.trustwave.com/en-us/resources/security-resources/security-advisories/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.