Security Advisory

CVE-2021-35228

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-21 17:43:01
Last updated 2024-09-16 23:56:04
Assigner SolarWinds
CVSS score 5.5
State PUBLISHED

Description

This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.