CVE-2024-45712

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*

History

18 Nov 2025, 21:45

Type Values Removed Values Added
CPE cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
References () https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-1_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-1_release_notes.htm - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45712 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45712 - Patch, Vendor Advisory
First Time Solarwinds
Solarwinds serv-u

Information

Published : 2025-04-15 09:15

Updated : 2025-11-18 21:45


NVD link : CVE-2024-45712

Mitre link : CVE-2024-45712

CVE.ORG link : CVE-2024-45712


JSON object : View

Products Affected

solarwinds

  • serv-u
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')