CVE-2024-45712

CVSS 3.1 Score 2.6 of 10 (low)

Details

Published Apr 15, 2025
CWE ID 79

Summary

CVE-2024-45712 refers to a client-side cross-site scripting (XSS) vulnerability in SolarWinds Serv-U. This issue allows an authenticated user, through their local machine and browser session, to inject malicious scripts into the Serv-U web interface. Despite the requirement for an authenticated account to exploit the vulnerability, the potential risk is still present, making it important for affected organizations to apply the available patch promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share