CVE-2024-45712
CVSS 3.1 Score 2.6 of 10 (low)
Details
Published Apr 15, 2025
CWE ID 79
Summary
CVE-2024-45712 refers to a client-side cross-site scripting (XSS) vulnerability in SolarWinds Serv-U. This issue allows an authenticated user, through their local machine and browser session, to inject malicious scripts into the Serv-U web interface. Despite the requirement for an authenticated account to exploit the vulnerability, the potential risk is still present, making it important for affected organizations to apply the available patch promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Serv-U
Affected Vendors
- SolarWinds