Unrated severityNVD Advisory· Published Oct 21, 2021· Updated Sep 16, 2024
Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388
CVE-2021-35228
Description
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <= 2021.3.7438
- Range: DPA 2021.3.7388
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.