VYPR
Unrated severityNVD Advisory· Published May 11, 2021· Updated Aug 3, 2024

CVE-2021-32604

CVE-2021-32604

Description

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SolarWinds Serv-U before 15.2.3 contains a stored XSS vulnerability in Share/IncomingWizard.htm via the SenderEmail parameter.

Vulnerability

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, leading to a stored cross-site scripting (XSS) vulnerability. The code path is reachable when a user interacts with the share file wizard functionality, and the parameter is not properly sanitized before being stored or rendered.

Exploitation

An attacker needs to supply a malicious payload in the SenderEmail parameter. This can be done by crafting a specially crafted URL or form submission. When the affected page processes the parameter, the injected script is stored and later executed in the context of other users' browsers who view the share wizard page. No authentication is explicitly required to trigger the stored XSS, as the vulnerable component may be accessible to unauthenticated users.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session token theft, account impersonation, defacement, or redirection to malicious sites. The attack results in information disclosure and potential compromise of the user's session within the SolarWinds Serv-U interface.

Mitigation

The vulnerability is fixed in SolarWinds Serv-U version 15.2.3. Users should upgrade to this version or later. No workarounds have been disclosed for versions prior to the fix. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.