#VU69540 OS Command Injection in Orion Platform - CVE-2022-36962
Published: November 23, 2022 / Updated: November 23, 2022
Orion Platform
SolarWinds
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the GetPdf function. A remote privileged user with complete control over the SolarWinds database can pass specially crafted data to the application and execute arbitrary OS commands on the target system.