Medium severity5.5NVD Advisory· Published Oct 21, 2021· Updated Jun 17, 2026
CVE-2021-35228
CVE-2021-35228
Description
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:solarwinds:database_performance_analyzer:2021.3.7388:*:*:*:*:*:*:*
- Range: DPA 2021.3.7388
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2021-3-7438_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2021-35228nvdVendor Advisory
News mentions
0No linked articles in our index yet.