#VU69539 Input validation error in Orion Platform - CVE-2022-36960
Published: November 23, 2022 / Updated: November 23, 2022
Orion Platform
SolarWinds
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the CheckWhetherNonAdminAttemptsToModifyBlacklistedRecords function in SolarWinds Web Console. A remote user can send specially crafted input to the application and execute arbitrary code on the system.