Description
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.
Problem types
CWE-20 Improper Input Validation
Product status
2023.3.1 and previous versions
Credits
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
References
documentation.solarwinds.com/...hco_2023-4_release_notes.htm
www.solarwinds.com/...ter/security-advisories/CVE-2023-40062